iptables, stateful checking using tcp sequence numbers

2002-06-13 Thread Williamson, Fionn
Hi All, I hope somebody can assist me in finding information about this... Please consider the following argument: Although the TCP sequence numbers may get sent to the log file (if logging is turned on for a rule), if it not present in the state table (/proc/net/ip_conntrack), then it is not

Re: iptables, stateful checking using tcp sequence numbers

2002-06-13 Thread Matthew Hellman
Although the TCP sequence numbers may get sent to the log file (if logging is turned on for a rule), if it not present in the state table (/proc/net/ip_conntrack), then it is not used to maintain state. However, I cannot verify that Firewall-1 does this as well (although any good firewall

IPTables, stateful checking using tcp sequence numbers

2002-05-07 Thread Williamson, Fionn
Hi All, * I'm posting the below on behalf of one of my colleagues: * I hope somebody can assist me in finding information about

Re: IPTables, stateful checking using tcp sequence numbers

2002-05-07 Thread Denis Ducamp
On Tue, May 07, 2002 at 12:17:23PM +0200, Williamson, Fionn wrote: Hi All, Hi, Can anybody PLEASE tell me: 1. if the sequence numbers are actually used in iptables to MAINTAIN the state of a connection, or if it is merely used to ESTABLISH connections, and thereafter ignored. No, they