El 06/07/11 11:05, Tom Eastep escribió:
On Wed, 2011-07-06 at 06:48 -0700, Tom Eastep wrote:
On Tue, 2011-07-05 at 21:05 -0700, Tom Eastep wrote:
On Jul 5, 2011, at 5:46 PM, Ricardo Rios wrote:
> When i connect from Box-2 to any ftp, works all ok, but when i try to
> connect from Box-1 i get this on /var/log/firewall
>
> 21:37:40 insert-master kernel: [832161.057782] nf_ct_ftp: dropping
> packetIN=eth4 OUT= MAC=00:0a:cd:1a:d1:95:00:22:6b:be:3c:41:08:00
> SRC=66.199.187.46 DST=192.168.41.1 LEN=102 TOS=0x00 PREC=0x00 TTL=45
> ID=30239 DF PROTO=TCP SPT=21 DPT=50892 SEQ=698644583 ACK=3438176321
> WINDOW=46 RES=0x00 ACK PSH URGP=0 OPT (0101080A932DFE0231935CF7) MARK=0x1
>
Obviously, the URL is http://www.shorewall.net/FTP.html
The message you are seeing is not generated by Shorewall but is
rather generated by the FTP connection tracking helper in the kernel.
I don't find it in the kernel source I have here locally (2.6.32).
I've done a bit of looking around on the Web and it appears that this
message has replaced the traditional 'partial' message mentioned in
Shorewall FTP HOWTO. It means that a message (probably a PASV REPLY)
is not complete because it was split between two packets.
I've seen this problem connecting to a particular FTP server, but I've
never seen it on all servers from a local network. Makes me think that
the ftp helper on that firewall is *not* working correctly.
-Tom
--
Tom Eastep \ When I die, I want to go like my Grandfather who
Shoreline, \ died peacefully in his sleep. Not screaming like
Washington, USA \ all of the passengers in his car
http://shorewall.net \________________________________________________
I just check kernel versions on both servers and i found the server
working good have kerne-default, and the server who is not working right
with the ftp helper have the kernel-desktop, dunno if that is the
problem but i going to install kernel-default and try.
------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security
threats, fraudulent activity, and more. Splunk takes this data and makes
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users