Hello,

I am analyzing IP masquerade module with the source,
and I found a doubtful part in it.

At the TCP state transition table (in the file "ip_masq.c"),
TCP state never transits to 'mLA'(LAST_ACK), because the
state is transited by only itself.

I suppose that the 'OUTPUT transit state' when a fin packet is received
shoud be 'mLA' like below.

-------
struct masq_tcp_states_t masq_tcp_states [] = {
/*      INPUT */
/*        mNO, mES, mSS, mSR, mFW, mTW, mCL, mCW, mLA, mLI      */
/*syn*/ {{mSR, mES, mES, mSR, mSR, mSR, mSR, mSR, mSR, mSR }},
/*fin*/ {{mCL, mCW, mSS, mTW, mTW, mTW, mCL, mCW, mLA, mLI }},
/*ack*/ {{mCL, mES, mSS, mSR, mFW, mTW, mCL, mCW, mCL, mLI }},
/*rst*/ {{mCL, mCL, mCL, mSR, mCL, mCL, mCL, mCL, mLA, mLI }},

/*      OUTPUT */
/*        mNO, mES, mSS, mSR, mFW, mTW, mCL, mCW, mLA, mLI      */
/*syn*/ {{mSS, mES, mSS, mES, mSS, mSS, mSS, mSS, mSS, mLI }},
/*fin*/ {{mTW, mFW, mSS, mTW, mFW, mTW, mCL, /*mTW*/mLA, mLA, mLI }},
/*ack*/ {{mES, mES, mSS, mSR, mFW, mTW, mCL, mCW, mLA, mES }},
/*rst*/ {{mCL, mCL, mSS, mCL, mCL, mTW, mCL, mCL, mCL, mCL }},
};
-------


Therefore the original code transits to mTW(TIME_WAIT),
after a ftp control connection is closed, the entry remains
2 minutes by default.

If the ftp client, during the 2 minutes, used same source port number
for new connection request to the same ftp server, IP masquerade
re-use the same entry with the old sequence number gap.
In this case, ftp communication may stop.

Fortunately, client will use other port number for new connection,
problem will not occur.


Is this wrong doubt?

-+*/
Hisao Nakashima


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to