El 06/07/11 11:05, Tom Eastep escribió:
On Wed, 2011-07-06 at 06:48 -0700, Tom Eastep wrote:
On Tue, 2011-07-05 at 21:05 -0700, Tom Eastep wrote:
On Jul 5, 2011, at 5:46 PM, Ricardo Rios wrote:
>  When i connect from Box-2 to any ftp, works all ok, but when i try to
>  connect from Box-1 i get this on /var/log/firewall
>
>  21:37:40 insert-master kernel: [832161.057782] nf_ct_ftp: dropping
>  packetIN=eth4 OUT= MAC=00:0a:cd:1a:d1:95:00:22:6b:be:3c:41:08:00
>  SRC=66.199.187.46 DST=192.168.41.1 LEN=102 TOS=0x00 PREC=0x00 TTL=45
>  ID=30239 DF PROTO=TCP SPT=21 DPT=50892 SEQ=698644583 ACK=3438176321
>  WINDOW=46 RES=0x00 ACK PSH URGP=0 OPT (0101080A932DFE0231935CF7) MARK=0x1
>
Obviously, the URL is http://www.shorewall.net/FTP.html

The message you are seeing is not generated by Shorewall but is rather generated by the FTP connection tracking helper in the kernel. I don't find it in the kernel source I have here locally (2.6.32).

I've done a bit of looking around on the Web and it appears that this message has replaced the traditional 'partial' message mentioned in Shorewall FTP HOWTO. It means that a message (probably a PASV REPLY) is not complete because it was split between two packets.

I've seen this problem connecting to a particular FTP server, but I've never seen it on all servers from a local network. Makes me think that the ftp helper on that firewall is *not* working correctly.

-Tom
--
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net  \________________________________________________


I just check kernel versions on both servers and i found the server working good have kerne-default, and the server who is not working right with the ftp helper have the kernel-desktop, dunno if that is the problem but i going to install kernel-default and try.
------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to