FreeBSD & Stack TCP/IP

From: Julien (nyc1660_at_freesurf.fr)
Date: 09/30/04


Date: Thu, 30 Sep 2004 10:56:14 +0200

Hi,

I have a router (FreeBSD 5.2) connected to the Internet (PPPoE) and a local
network with few computers (Win & xBSD).

If I tried to send a TCP packet with the FIN flag to my FreeBSD on the local
interface ... I got no anwser which is normal (I guess).

If I tried to send the same packet (with FIN flag) to my FreeBSD but from
the Internet, I got an answer with the RST, PUSH and SYN flags.

I do not understant why I have TWO DIFFERENT behavior.

I can give few information here :
- I use ipfw (without check state rules) and natd.
- On my local network, the fw lets every packets go through.
- My kernel is NOT compiled with TCP_DROP_SYNFIN option and sysctl gives me
''net.inet.tcp.drop_synfin=0'.
- My router is pingable on both interfaces.
- I tried to send a FIN packet on another FreeBSD on my local network, I got
no answer.

If anyone knows. Thanx

Julien



Relevant Pages

  • RE: Freebsd Theme Song
    ... from the network into the ethernet receiver. ... It takes a certain amount of time to get the packet out of ... At low data rates polling is less ... >Subject: Re: Freebsd Theme Song ...
    (freebsd-questions)
  • Stack TCP/IP & FreeBSD
    ... If I tried to send a TCP packet with the FIN flag to my FreeBSD on the local ... On my local network, the fw lets every packets go through. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: IPFW: Need some help
    ... I'm new to *nix and now, while configuring IPFW Firewall on FreeBSD ... After packet from my network is passed to natd demon - it is returning ...
    (freebsd-questions)
  • Re: risks of ip-forwarding, without ipf/ipfw
    ... > I run a FreeBSD router/firewall for my home network, ... say to itself "no match" and drop the packet ... access to your LAN. ...
    (FreeBSD-Security)
  • alt.2600 FAQ Revision .014 (2/4)
    ... One type of firewall is the packet filtering firewall. ... Dropping packets instead of rejecting them greatly increases the time required to scan your network. ... Port scanning UDP ports is much slower than port scanning TCP ports. ... Chartreuse Use the electricity from your phone line Cheese Connect two phones to create a diverter Chrome Manipulate Traffic Signals by Remote Control ...
    (alt.2600)