NetFilter
[Top] [All Lists]

Re: Dropped fin acks (iptables + lvs)

To: netfilter@lists.netfilter.org
Subject: Re: Dropped fin acks (iptables + lvs)
From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
Date: Sat, 27 Jan 2007 17:19:44 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <Pine.LNX.4.61.0701242315170.32656@yvahk01.tjqt.qr>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: Plouf !
References: <163461433411784@lycos-europe.com> <Pine.LNX.4.61.0701242315170.32656@yvahk01.tjqt.qr>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Mozilla Thunderbird 1.0.6 (Windows/20050716)
Hello,

Jan Engelhardt a écrit :
I am running iptables and lvs on two boxes loadbalancing http[s] and ssh 
traffic to two real servers.
Everything is working just fine from the users point of view. However, I keep seeing a lot of dropped packets of type ack/fin and ack/rst in my iptables log. Seems like the connection tracking isn't working the way I expect it to.

RST-ACK is received as a response to SYN to a closed port, and hence, is not part of a connection.

At Netfilter connection tracking level, ACK/RST in response to SYN is part of a connection and is supposed to be in the ESTABLISHED state, even though at TCP level the connection is not established.


<Prev in Thread] Current Thread [Next in Thread>