Re: [PATCH nf-next] netfilter: nf_conntrack_tcp: skip tracking for offloaded packets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> Sometimes flowtable datapath passes up packets to classic forwarding
> path, eg. mtu exceeded case. Skip TCP tracking otherwise these packets
> are considered invalid by conntrack.

They are?  nft_flow_offload_eval() sets IP_CT_TCP_FLAG_BE_LIBERAL for
the conntrack, so at least window checks are disabled.



[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux