Hi
I am having trouble with FTP connections from inside the firewall and I get the following messages in live filter log and in kernal log.
I would really appreciate if someone could tell me what these messages mean and why packets are getting dropped.
thanks
10:16:53 64.235.244.161 20 -> 209.82.115.126 4614 TCP 40 57 [Invalid packet (dropped by validator)] DF WINDOW=62780 RES=0x00 ACK FIN URGP=0
10:16:56 64.235.244.161 20 -> 209.82.115.126 4614 TCP 40 57 [Invalid packet (dropped by validator)] DF WINDOW=62780 RES=0x00 ACK FIN URGP=0
10:17:02 64.235.244.161 20 -> 209.82.115.126 4614 TCP 40 57 [Invalid packet (dropped by validator)] DF WINDOW=62780 RES=0x00 ACK FIN URGP=0
10:17:14 64.235.244.161 20 -> 209.82.115.126 4614 TCP 40 57 [Invalid packet (dropped by validator)] DF WINDOW=62780 RES=0x00 ACK FIN URGP=
10:17:38 64.235.244.161 20 -> 209.82.115.126 4614 TCP 40 57 [Invalid packet (dropped by validator)] DF WINDOW=62780 RES=0x00 ACK FIN URGP=0
10:18:26 64.235.244.161 20 -> 209.82.115.126 4614 TCP 40 57 [Invalid packet (dropped by validator)] DF WINDOW=62780 RES=0x00 ACK FIN URGP=0
Here is the Kernal log for an Ftp connection from outside
2005:03:15-09:46:25 (none) kernel: ip_conntrack_expect_related c53de080 (ftp)
2005:03:15-09:46:25 (none) kernel: tuple: 6 81.75.237.32:0 -> 209.82.100.25:1679
2005:03:15-09:46:25 (none) kernel: mask: 65535 255.255.255.255:0 -> 255.255.255.255:65535
2005:03:15-09:46:25 (none) kernel: ip_conntrack_change_expect: c7a26480 (ftp)
2005:03:15-09:46:25 (none) kernel: exp tuple: 6 81.75.237.32:0 -> 209.82.100.25:1679
2005:03:15-09:46:25 (none) kernel: exp mask: 65535 255.255.255.255:0 -> 255.255.255.255:65535
2005:03:15-09:46:25 (none) kernel: newtuple: 6 81.75.237.32:0 -> 209.82.100.25:1679
2005:03:15-09:46:49 (none) kernel: ip_conntrack_expect_related c53de080 (ftp)
2005:03:15-09:46:49 (none) kernel: tuple: 6 81.75.237.32:0 -> 209.82.100.25:1680
2005:03:15-09:46:49 (none) kernel: mask: 65535 255.255.255.255:0 -> 255.255.255.255:65535
2005:03:15-09:46:49 (none) kernel: ip_conntrack_change_expect: c7a26c80 (ftp)
2005:03:15-09:46:49 (none) kernel: exp tuple: 6 81.75.237.32:0 -> 209.82.100.25:1680
2005:03:15-09:46:49 (none) kernel: exp mask: 65535 255.255.255.255:0 -> 255.255.255.255:65535
2005:03:15-09:46:49 (none) kernel: newtuple: 6 81.75.237.32:0 -> 209.82.100.25:1680
2005:03:15-09:47:20 (none) kernel: ip_conntrack_expect_related c53de080 (ftp)
2005:03:15-09:47:20 (none) kernel: tuple: 6 81.75.237.32:0 -> 209.82.100.25:1681
2005:03:15-09:47:20 (none) kernel: mask: 65535 255.255.255.255:0 -> 255.255.255.255:65535
2005:03:15-09:47:20 (none) kernel: ip_conntrack_change_expect: c7a26480 (ftp)
2005:03:15-09:47:20 (none) kernel: exp tuple: 6 81.75.237.32:0 -> 209.82.100.25:1681
2005:03:15-09:47:20 (none) kernel: exp mask: 65535 255.255.255.255:0 -> 255.255.255.255:65535
2005:03:15-09:47:20 (none) kernel: newtuple: 6 81.75.237.32:0 -> 209.82.100.25:1681
This thread was automatically locked due to age.