Re: Routing issues - ping works one way but not the other



On Tue, 12 Oct 2010 15:07:45 +0200, Pascal Hambourg wrote:

Because box A's connection tracking state machine did not see the echo
request it replies to, due to the asymmetric routing. In the other way,
box A sees the echo request which has state NEW, and does not see the
echo reply, but that does not matter.

Is there any way to "fix" this by sharing connection state amongst
multiple routers? I'm imaging that this would be tough at best given the
speeds involved. Packets used to share state between routers would have
to be quicker than the reply packets to newly established connections.

On the other hand, this sounds like a fairly common problem.

- Andrew
.



Relevant Pages

  • Re: [Full-disclosure] ICMP Security Vulnerabilities - NEW (cough)
    ... egress filtering based on the ICMP payload. ... When a host receives the request, ... >Allow the outbound echo request and inbound echo reply. ... >sender to slow down the rate it is sending packets. ...
    (Bugtraq)
  • Re: [Full-disclosure] ICMP Security Vulnerabilities - NEW (cough)
    ... egress filtering based on the ICMP payload. ... When a host receives the request, ... >Allow the outbound echo request and inbound echo reply. ... >sender to slow down the rate it is sending packets. ...
    (Full-Disclosure)
  • Filtering on IPSEC
    ... I've setup my first IPSEC VPN beetween FreeBSD 8.2 and CheckPoint VPN-1. ... All is working fine, but I get a strange behavior: outgoing packets go via enc0, while incoming packets arrive in gif0. ... To be precise, setting to '3' all the net.enc.* sysctls and sending a ping via vpn, I see the echo request, the encapsulated echo request, the encapsulated echo reply on enc0 and the echo reply on gif0. ...
    (freebsd-net)
  • Re: Packet routing between interfaces
    ... >>from another poster to use tcpdump, I determined that the echo request ... > return the packets destined for a different subnet. ... The device is a xDSL modem that is used for my internet connection. ... Remove all numbers, then remove invalid, email, no, and spam to reply. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: "ping" with packets larger then 25152 bytes fails.
    ... then 25152 bytes, "ping" fails. ... ECHO REQUEST or ICMP ECHO REPLY packets, ...
    (freebsd-net)