IPtables and Connection Tracking

2002-04-26 Thread Thorsten Kruschel
Hi,

today I saw something mysterious with IPtables. I had a little mistake
in my script. To test the funktionality. i pinged a host in the www and
changed then the wrong entries in my script. I looked with tcpdump if
the ping becomes a reply. But erverything i've done, no reply came back.

Then i pinged from another maschine in the same subnet and i've become a
reply.

Does the connection tracking hold the connections even if the firewall
was flushed?

If it is so, is it a bug or a feature?

Thanks to all

Thorsten




-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Big ICMP with don't Fragment bit

2002-04-11 Thread Thorsten Kruschel

Hi all,

has anybody an Idea how to create an ICMP Packet with size of 1500 and
don't Fragment bit set? Or how to filter such Packets generally with
IPChains?

I've the Problem, that a Maschine cancels the external connection some
times. No entrys in Syslog or anywhere else.
In my Intrusion Detection I see some maschines sending such Packets
before the Maschine cancels the Connection to the external Net. 

Thorsten


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]




Big ICMP with don't Fragment bit

2002-04-11 Thread Thorsten Kruschel
Hi all,

has anybody an Idea how to create an ICMP Packet with size of 1500 and
don't Fragment bit set? Or how to filter such Packets generally with
IPChains?

I've the Problem, that a Maschine cancels the external connection some
times. No entrys in Syslog or anywhere else.
In my Intrusion Detection I see some maschines sending such Packets
before the Maschine cancels the Connection to the external Net. 

Thorsten


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]