Re: Simulating router breaking idle TCP connections with IPTABLES

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



>Hi All,

>
>It seems there are some routers floating around that break idle TCP connections after a specified amount of time. 
>For example: "Sonicwall devices have that feature to close established connections when they hit a predefined timeout value
>with no data passing through."
>
>This causes some issues with Gnome's Nautilus/GVFS and sftp connections that I'm trying to handle more gracfully. The problem is I >dont have a router that has this behaviour so I'm looking for a way to simulate it using iptables on my PC.
>I have read the thread about this from 2011 http://www.spinics.net/lists/netfilter/msg51963.html but it looks like a solution wasnt provided >as the usecase didnt call for doing what was requested.
>I however DO want to break the established TCP connections. Does anyone know how I can do this? I don't mind if I need to edit code >and rebuild as this is just for testing perposes so I will be reverting once I'm finished.
>
>Thanks for your time,
>Tim

To be a little bit clearer I want to causse the behaviour described in section 2.4 here: http://tldp.org/HOWTO/TCP-Keepalive-HOWTO/overview.html

Where the TCP connection is still thought to be active to the peers but the proxy/firewall has no knowlegde on the connection and so the connection breaks up. 
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux