[Bug 816400] New: SuSEfirewall2 rejects ICMP packets it should accept.
https://bugzilla.novell.com/show_bug.cgi?id=816400 https://bugzilla.novell.com/show_bug.cgi?id=816400#c0 Summary: SuSEfirewall2 rejects ICMP packets it should accept. Classification: openSUSE Product: openSUSE 12.1 Version: Final Platform: x86-64 OS/Version: openSUSE 12.1 Status: NEW Severity: Normal Priority: P5 - None Component: Network AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: carlos.e.r@opensuse.org QAContact: qa-bugs@suse.de Found By: --- Blocker: --- I get quite a number of these in my firewall log: <0.4> 2013-04-10 01:41:09 Telcontar kernel - - - [1145683.188480] SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:21:85:16:2d:0b:00:30:da:70:d7:ea:08:00 SRC=192.168.1.1 DST=192.168.1.14 LEN=92 TOS=0x00 PREC=0xC0 TTL=255 ID=40362 PROTO=ICMP TYPE=3 CODE=0 [SRC=192.168.1.14 DST=80.58.61.254 LEN=64 TOS=0x00 PREC=0x00 TTL=64 ID=54990 PROTO=UDP SPT=24645 DPT=53 LEN=44 ] <0.4> 2013-04-19 23:35:57 Telcontar kernel - - - [1528647.700090] SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=00:21:85:16:2d:0b:00:30:da:70:d7:ea:08:00 SRC=192.168.1.1 DST=192.168.1.14 LEN=93 TOS=0x00 PREC=0xC0 TTL=255 ID=48789 PROTO=ICMP TYPE=3 CODE=0 [SRC=192.168.1.14 DST=80.58.61.250 LEN=65 TOS=0x00 PREC=0x00 TTL=64 ID=51914 PROTO=UDP SPT=22413 DPT=53 LEN=45 ] The router is informing the openSUSE machine that a packet that was sent to the ISP DNS server, can not pass. That ICMP message gets rejected. I have been told that this is a bug and to report it. More information here: http://lists.opensuse.org/opensuse/2013-04/msg00850.html They say that it affects all versions of openSUSE. I can not verify. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c
Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c1
Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c2
--- Comment #2 from Carlos Robinson
how often does it happen?
minutes? hours?
Even days. It is random. last one was about 3 hours ago.
We would need some kind of network dump I fear.
run: # tcpdump -i eth0 port 53 or icmp -w foo.pcap
Ok, running. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c3
Carlos Robinson
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c4
--- Comment #4 from Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c5
--- Comment #5 from Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c6
Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c7
--- Comment #7 from Carlos Robinson
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c8
--- Comment #8 from Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c
Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c9
Carlos Robinson
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c10
--- Comment #10 from Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c11
--- Comment #11 from Carlos Robinson
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c12
Marcus Meissner
https://bugzilla.novell.com/show_bug.cgi?id=816400
https://bugzilla.novell.com/show_bug.cgi?id=816400#c13
--- Comment #13 from Carlos Robinson
participants (1)
-
bugzilla_noreply@novell.com