OpenSolaris Solaris Forum  
     

Left Nav FAQ Members List Default Password Members List Linux Commands Search Today's Posts Mark Forums Read Right Nav

Left Container Right Container
 

Go Back   OpenSolaris Solaris Forum OpenSolaris Security

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-25-2011, 05:49 AM
Junior Member
 
Join Date: Oct 2011
Posts: 1
Question IPFilter: Packet gets blocked eventhough it should pass

Hi all,

In output of ipfstat, what is packet state(in) and packet state(out)? I get lost packets even when my state table is not full (i.e number of active entries(77)(from ipfstat -s command) in state table are much less than fr_statemax (16052)(from ipf -T list | grep state)). What may be the reason for this?
what is fr_statesize in ipf -T list | grep state output.
My Solaris10 system has IP Filter: v4.1.9 (592).


> ipfstat


bad packets: in 0 out 0
IPv6 packets: in 0 out 0
input packets: blocked 17387 passed 2719576 nomatch 550284 counted 0 short 0
output packets: blocked 270 passed 3198584 nomatch 1179066 counted 0 short 0
input packets logged: blocked 17387 passed 0
output packets logged: blocked 270 passed 0
packets logged: input 0 output 0
log failures: input 0 output 0
fragment state(in): kept 0 lost 0 not fragmented 0
fragment state(out): kept 0 lost 0 not fragmented 0
packet state(in): kept 22459 lost 133
packet state(out): kept 61873 lost 24129

ICMP replies: 0 TCP RSTs sent: 4736
Invalid source(in): 0
Result cache hits(in): 0 (out): 0
IN Pullups succeeded: 360 failed: 0
OUT Pullups succeeded: 401 failed: 0
Fastroute successes: 4736 failures: 0
TCP cksum fails(in): 0 (out): 0
IPF Ticks: 141315
Packet log flags set: (0)

> ipfstat -s
IP states added:
6033 TCP
9804 UDP
70993 ICMP
3735144 hits
1915993 misses
0 maximum
0 no memory
77 active
0 expired
0 closed
State logging enabled

State table bucket statistics:
76 in use

0 max bucket
0.82% bucket usage
0 minimal length
2 maximal length
1.013 average length

> ipf -T list | grep state

fr_statemax min 0x1 max 0x7fffffff current 16052
fr_statesize min 0x1 max 0x7fffffff current 9233

fr_state_lock min 0 max 0x1 current 0
fr_state_maxbucket min 0x1 max 0x7fffffff current 28
fr_state_maxbucket_reset min 0 max 0x1 current 1
ipstate_logging min 0 max 0x1 current 1
state_flush_level_hi min 0x1 max 0x64 current 95
state_flush_level_lo min 0x1 max 0x64 current 75
Reply With Quote
Sponsored Links

Reply

Bookmarks

Tags
ipfilter, solaris, state table, statetable

Thread Tools
Display Modes

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:37 PM.


Powered by vBulletin. Copyright 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.