> Hello,
> 
> I am analyzing IP masquerade module with the source,
> and I found a doubtful part in it.
> 
> At the TCP state transition table (in the file "ip_masq.c"),
> TCP state never transits to 'mLA'(LAST_ACK), because the
> state is transited by only itself.
> 
> I suppose that the 'OUTPUT transit state' when a fin packet is received
> shoud be 'mLA' like below.
> 
> -------
> struct masq_tcp_states_t masq_tcp_states [] = {
> /*    INPUT */
> /*      mNO, mES, mSS, mSR, mFW, mTW, mCL, mCW, mLA, mLI      */
> /*syn*/       {{mSR, mES, mES, mSR, mSR, mSR, mSR, mSR, mSR, mSR }},
> /*fin*/       {{mCL, mCW, mSS, mTW, mTW, mTW, mCL, mCW, mLA, mLI }},
> /*ack*/       {{mCL, mES, mSS, mSR, mFW, mTW, mCL, mCW, mCL, mLI }},
> /*rst*/ {{mCL, mCL, mCL, mSR, mCL, mCL, mCL, mCL, mLA, mLI }},
> 
> /*    OUTPUT */
> /*      mNO, mES, mSS, mSR, mFW, mTW, mCL, mCW, mLA, mLI      */
> /*syn*/       {{mSS, mES, mSS, mES, mSS, mSS, mSS, mSS, mSS, mLI }},
> /*fin*/       {{mTW, mFW, mSS, mTW, mFW, mTW, mCL, /*mTW*/mLA, mLA, mLI }},
> /*ack*/       {{mES, mES, mSS, mSR, mFW, mTW, mCL, mCW, mLA, mES }},
> /*rst*/ {{mCL, mCL, mSS, mCL, mCL, mTW, mCL, mCL, mCL, mCL }},
> };
> -------
> 
> 
> Therefore the original code transits to mTW(TIME_WAIT),
> after a ftp control connection is closed, the entry remains
> 2 minutes by default.
> 
> If the ftp client, during the 2 minutes, used same source port number
> for new connection request to the same ftp server, IP masquerade
> re-use the same entry with the old sequence number gap.
> In this case, ftp communication may stop.
> 
> Fortunately, client will use other port number for new connection,
> problem will not occur.
> 
> 
> Is this wrong doubt?

You are probably correct. I have suspected for some time that there was
an error in state transition, because Masq is not correctly closing TCP
connections under certain, heavily loaded conditions. For example, I
utilise a daemon which connects via a masq to a machine outside. When this
connection does not deliver the data expected, the connection is closed,
and a new one initiated almost immediately. This has resulted in hundreds
of daemons hanging on the remote machine, and TCP sockets not clearing out
for some time because they believe they haven't yet closed.

I am not sure whether the symptoms I have experienced match with those you
have indicated, but I'd love to find out :)

Richard.



_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to