Bug 11797
Summary: | IPv6 conntrack treats neighbour and router solicitation packets as invalid | ||
---|---|---|---|
Product: | Networking | Reporter: | Marek Szuba (Marek.Szuba) |
Component: | Netfilter/Iptables | Assignee: | networking_netfilter-iptables (networking_netfilter-iptables) |
Status: | REJECTED WILL_NOT_FIX | ||
Severity: | normal | ||
Priority: | P1 | ||
Hardware: | All | ||
OS: | Linux | ||
Kernel Version: | 2.6.25 | Subsystem: | |
Regression: | --- | Bisected commit-id: | |
Attachments: | A patch to add the two ICMPv6 solicitation types to the "valid new" list. |
Description
Marek Szuba
2008-10-20 15:24:32 UTC
Created attachment 18387 [details] A patch to add the two ICMPv6 solicitation types to the "valid new" list. Attaching a proposed solution to the problem - the patch adds "router solicitation" and "neighbour solicitation" to the list of ICMPv6 types IPv6 conntrack considers allowed to initiate new connections. PS. This problem was discovered and (hopefully) fixed collaboratively by Ćukasz Stelmach <steelman@post.pl> and myself, please attribute both of us should the patch make it into the kernel tree. Thanks for the report and patch. This makes sense to me, but please send the patch and the problem description to netfilter-devel@vger.kernel.org and CC Yasuyuki KOZAKAI <yasuyuki.kozakai@toshiba.co.jp>, who is more knowledgable about this subject than me (bugzilla doesn't allow me to CC him myself). Thanks. According to this post by Yasuyuki Kozakai to netfilter-devel http://marc.info/?l=netfilter-devel&m=122586255301143&w=2 the issue requires a more complex solution. As such, this bug report was requested to be rejected. |