News: This forum is now permanently frozen.
Pages: [1]
Topic: IPfilter bug  (Read 9848 times)
« on: May 01, 2007, 17:14:52 »
Hillel *
Posts: 7

I found a few references to the bug in ipfilter with FreeBSD 6.1 that causes packets to be blocked with "out of window" errors when the filter rules specify the "keep state" option.  See the "RSH blocked from WAN to LAN" thread in the General Questions forum.

A Google Groups search turns up a few references that the bug was fixed in the 6.2-CURRENT distribution.  It could be that the prerelease 6.2 distributions used for the m0n0wall 1.3 beta so far still have the bug.

Could the next 1.3 beta release include ipfilter from the FreeBSD 6.2-CURRENT distribution?
« Reply #1 on: May 02, 2007, 01:14:33 »
cmb *****
Posts: 851

I'm glad to hear you've found reference to this issue.

Your terminology is mixed up. There is no 6.2-CURRENT. FreeBSD-CURRENT is what will become 7.0. 6-STABLE, a.k.a. RELENG_6, is what will become 6.3 when it's released. 6.2 is out, the only branch based on it is RELENG_6_2, and it'll likely only get security fixes.

It's possible the fix is only in -CURRENT, which may make it difficult to back port to RELENG_6, or it's possible it's in RELENG_6 or RELENG_6_2 already.

Can you provide links to the threads you see referencing this so we can see what this fix is and where it's been committed?
« Reply #2 on: May 02, 2007, 21:24:26 »
Hillel *
Posts: 7

Sorry about the terminology mixup.  I don't do any development with FreeBSD.

Here is one reference with FreeBSD 6.1  and also a Google Groups search turns up a discussion on mailing.unix.ipfilter  about patching ipfilter in FreeBSD 6.2.

A relevant quote:
|>Is there a patch for the keep state/OOW-issues in version 4.1.13 on
|>FreeBSD6.2 and if so, what are the instructions to apply the patch?
|
|You can just copy /sys/config/ipfilter/netinet/ip_state.c from -current.
|As far as I can determine, the only changes are the OOW fixes.
« Last Edit: May 02, 2007, 21:26:59 by Hillel »
« Reply #3 on: May 03, 2007, 00:45:14 »
cmb *****
Posts: 851

Thanks!  Hopefully Manuel will note this and possibly include it in the next 1.3 release. I think this fixes the issue Paul Taylor was seeing (see m0n0wall-dev post from him), and others are likely seeing as well.
« Reply #4 on: May 04, 2007, 21:10:10 »
Manuel Kasper
Administrator
*****
Posts: 364

Noted - I'll make sure this fix is in the next release (even put it on http://m0n0.ch/wall/todo.php so I don't forget ;). Thanks for digging this up!
« Reply #5 on: August 10, 2007, 22:05:16 »
Hillel *
Posts: 7

I just tested m0n0wall v1.3b3.  Rsh commands are still being stuck after a good connection.  The only change is that if the rsh client keeps trying, it will occasionaly get through after a significant delay.  With 1.3b2, the rsh client would never get through for a few minutes after a good connection.  That still makes it impossible for us to really use m0n0wall.
« Reply #6 on: August 16, 2007, 17:56:12 »
Hillel *
Posts: 7

As a workaround, is there a way to specify a firewall rule so that connections to a specific port will not have the "keep state" option?
« Reply #7 on: December 07, 2007, 20:10:32 »
Hillel *
Posts: 7

Just tested the new 1.3b5 release.  It looks like the ipfilter
upgrade finally fixed the out-of-window problem on successive
remote shell and remote file copy requests.  They all seem to
work now.  I noticed some blocked packets in the firewall log
during a remote update using the SCO "rdist" utility, but that
all seemed to work out and not cause any trouble.

Thanks and great job, Manuel!
---Hillel
« Reply #8 on: June 01, 2008, 21:14:25 »
evilpete *
Posts: 9

I am running 1.3b11 and am still seeing problems with OOW problems (I have tried 1.233 but it did not help)

ssh and http connections work but SMTP fails everytime with OOW

my network layout is similar to  Network Diagram 14.1.1. in
http://doc.m0n0.ch/handbook/examples.html#id11622455

except I have my email/shell system on my internal network and I use the DMZ for WiFi and TiVO

Are their any known work arounds?
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines