Mailing List Archive

Re: *Very* strange netfilter or conntrack bug??
On Wed, 13 Jun 2001, Adam Ierymenko wrote:

> I think this is a netfilter bug, so I am posting this here. If I am
> posting this in the wrong place or if you don't think this is a
> netfilter bug feel free to direct me elsewhere.

[.different ping sessions always from host A to host B have wildly varying
latencies -- really strange!]

Have you gotten any closer to this bug?

I'm currently tracking down a problem that I think is connection tracking
/ NAT related and have just finished instrumenting the 2.4.3 stack and
netfilter with a lot of printk's. Figure the patch might help other
people...

It can be found at http://oss.one2one-networks.com/

Haven't had the chance to actually run any tests with it yet -- had to
fight a couple of makefile bugs in iptables first... patches will follow
soonish.

Our problem has to do with a machine that we route some modem traffic
through. The machine runs 2.4.3 with netfilter and redirects web traffic
from one IP address and from most IP addresses to a local port. Web
traffic from that one IP address is allowed to go straight through to two
specific IP addresses (external sites). The trouble is that we want to
change all this dynamically. After the first redirected web access we
want /stop/ redirecting web traffic. Some times it works flawlessly and
sometimes we introduce strange pauses in the IP traffic (15-30 seconds).
The only traffic to/from the machine at the time is IP traffic originating
from a dial-up machine. Triggering of the bug is very sensitive to the
exact access pattern, i.e. which URLs the dial-up machine accesses and in
which order.

-Peter

Memory is like orgasms, it's much better when you don't have to fake it.
- Seymour Cray