Re: ip_conntrack_ftp messages

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Phil Oester wrote:
On Mon, Nov 24, 2008 at 01:28:09PM +0100, Patrick McHardy wrote:
Rusty Russell wrote:
On Monday 24 November 2008 10:43:19 Shane Goulden wrote:
2.6.18-92.1.10.el5xen

FTP is working. Is there a way to easily silence the messages?
Not that I am aware of. Perhaps that printk (still there in latest kernels) should be downgraded to a DEBUG?

Its strange that FTP is apparently working since we drop those packets.
I'm not sure about downgrading that message, its there to inform the
user of an exceptional action (dropping of packets within conntrack).

Shane, how do you trigger those messages?

I've seen these messages when something other than FTP is utilizing
port 21.  Perhaps we should have a bit in the conntrack helper which
stops looking on future packets if it doesn't see FTP traffic in the
beginning of the session?

That would make sense, but I can't see a good way to make this
decision except maybe when we seen non-ascii characters. But
even that will fail with different encodings. Do you have a
good idea?


--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux