tcp teardown delay?

From: /dev/null (dev'0x2e'null@BeginThread.com)
Date: 04/23/03


From: "/dev/null" <dev'0x2e'null@BeginThread.com>
Date: Wed, 23 Apr 2003 13:49:46 GMT

2.4.18 kernel

I'm seeing some long delays (~ 1.5 hr) on some tcp teardowns on connections
traversing my linux firewall and was wondering if this is normal. It ends
up tripping over my firewall (because the state awareness is gone by then)
and looking like a scan. Here's the pertinent logs at the end of the
connection starting with the first ACK FIN:

Apr 22 18:15:48 ALPHA kernel: incoming FORWARD: IN=eth0 OUT=eth2
SRC=207.68.172.245 DST=192.168.1.6 LEN=40 TOS=0x00 PREC=0x00 TTL=239
ID=59301 PROTO=TCP SPT=80 DPT=3778 WINDOW=8190 RES=0x00 ACK FIN URGP=0

Apr 22 18:15:48 ALPHA kernel: incoming FORWARD: IN=eth0 OUT=eth2
SRC=207.68.172.245 DST=192.168.1.6 LEN=40 TOS=0x00 PREC=0x00 TTL=239
ID=59303 PROTO=TCP SPT=80 DPT=3777 WINDOW=8190 RES=0x00 ACK FIN URGP=0

Apr 22 18:15:48 ALPHA kernel: incoming FORWARD: IN=eth2 OUT=eth0
SRC=192.168.1.6 DST=207.68.172.245 LEN=40 TOS=0x00 PREC=0x00 TTL=127
ID=61164 DF PROTO=TCP SPT=3777 DPT=80 WINDOW=8760 RES=0x00 ACK URGP=0

Apr 22 18:15:49 ALPHA kernel: incoming FORWARD: IN=eth0 OUT=eth2
SRC=207.68.172.245 DST=192.168.1.6 LEN=40 TOS=0x00 PREC=0x00 TTL=239
ID=18236 PROTO=TCP SPT=80 DPT=3778 WINDOW=8190 RES=0x00 ACK FIN URGP=0

Apr 22 18:15:49 ALPHA kernel: incoming FORWARD: IN=eth2 OUT=eth0
SRC=192.168.1.6 DST=207.68.172.245 LEN=40 TOS=0x00 PREC=0x00 TTL=127
ID=61420 DF PROTO=TCP SPT=3778 DPT=80 WINDOW=8607 RES=0x00 ACK URGP=0

# two minutes later comes a reset, by then iptables forgot about this
connection and thinks it's input, not a forward:
Apr 22 18:17:26 ALPHA kernel: incoming INPUT: IN=eth0 OUT=
MAC=00:40:05:82:98:00:00:0a:42:6d:3c:a8:08:00 SRC=207.68.172.245
DST=XXX.TER.NAL.IP LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=8405 PROTO=TCP
SPT=80 DPT=3778 WINDOW=9300 RES=0x00 RST URGP=0

# so it drops it and looks like a scan in the logs (until I pull the whole
connection):
Apr 22 18:17:26 ALPHA kernel: Default DROPing INPUT: IN=eth0 OUT=
MAC=00:40:05:82:98:00:00:0a:42:6d:3c:a8:08:00 SRC=207.68.172.245
DST=XXX.TER.NAL.IP LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=8405 PROTO=TCP
SPT=80 DPT=3778 WINDOW=9300 RES=0x00 RST URGP=0

# And again because the first one was DROPed
Apr 22 18:17:26 ALPHA kernel: incoming INPUT: IN=eth0 OUT=
MAC=00:40:05:82:98:00:00:0a:42:6d:3c:a8:08:00 SRC=207.68.172.245
DST=XXX.TER.NAL.IP LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=8408 PROTO=TCP
SPT=80 DPT=3777 WINDOW=9300 RES=0x00 RST URGP=0

# And it DROPs to, looking like two scans per second:
Apr 22 18:17:26 ALPHA kernel: Def DROPing INPUT: IN=eth0 OUT=
MAC=00:40:05:82:98:00:00:0a:42:6d:3c:a8:08:00 SRC=207.68.172.245
DST=XXX.TER.NAL.IP LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=8408 PROTO=TCP
SPT=80 DPT=3777 WINDOW=9300 RES=0x00 RST URGP=0

# finally the client machine decides it needs to reset the connection, over
an hour and a half later:
Apr 22 19:48:21 ALPHA kernel: incoming FORWARD: IN=eth2 OUT=eth0
SRC=192.168.1.6 DST=207.68.172.245 LEN=40 TOS=0x00 PREC=0x00 TTL=127
ID=41499 DF PROTO=TCP SPT=3778 DPT=80 WINDOW=0 RES=0x00 RST URGP=0

The client machine is windoze if that helps (I find it usually hurts...).

Why are these two trying to do resets after ACK FIN? And then why does the
client try to reset after an hour and a half?

Thanks for any insight.



Relevant Pages

  • Re: IP address and LAN problems
    ... Winsock checks after I had reset. ... then able to connect to Tiscali, but the LAN connection is broken. ... years until the broadband network failed for a week over Xmas. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Dial-up clients drop connections
    ... Both products physically synchronize with the respondent modem, authenticate, attempt to "talk to the network", then drop the connection. ... Extreme cases may warrant the removal of the TCP/IP protocol..With the NetShell utility, you can reset the TCP/IP stack to restore it to its state that existed when the operating system was installed. ... When you run the reset command, it rewrites pertinent registry keys that are used by the Internet Protocol stack to reach the same result as the removal and the reinstallation of the protocol. ...
    (microsoft.public.windowsxp.general)
  • Re: no picture on LG dvd player
    ... I checked out his manual online and didn't see any instructions for a reset. ... It's connected via a yellow analog connection to my old Sony TV. ...
    (rec.video.dvd.players)
  • RE: acer aspire one - wireless ethernet
    ... connection to the router and it has a static IP address. ... Everything except for the laptops has a static IP address. ... from the Acer after copying a large file and losing the connection, ... If I leave everything else alone after the lockup and just reset ...
    (Fedora)
  • Re: Resetting Buffalo logins and password
    ... mistake on a family member's part reset the everything. ... Is that *YOUR* wireless router or the neighbors. ... randomly changed the mac address (I think I incremented the last digit ... It also appears that you must setup the WAN connection for DHCP. ...
    (alt.internet.wireless)

Loading