Quantcast
Viewing all articles
Browse latest Browse all 19115

0008580: GRE packets seen as --state INVALID by iptables after kernel update

updated from kernel-2.6.32-504.8.1.el6.x86_64 to kernel-2.6.32-504.12.2.el6.x86_64 after the update I could not connect to any of the PPTP VPN's. This issue is also present in kernel-2.6.32-504.16.2.el6.x86_64.<br /> IPTABLES is setup as Log & Drop --log-prefix FORWARD Pkt Invalid:. <br /> After tyhe kernel update I get FORWARD Pkt Invalid: IN=eth0 OUT=eth1 SRC=10.70.70.15 DST=195.XXX.XXX.40 LEN=57 TOS=0x00 PREC=0x00 TTL=127 ID=21635 PROTO=47 logged.<br /> The --state INVALID rule is the first rule in the FORWARD chain<br /> Iptable rules for the Forward Invalid<br /> -A FORWARD -m state --state INVALID -j LOG --log-prefix "DROP: FORWARD Pkt Invalid: " --log-tcp-options --log-ip-options<br /> -A FORWARD -m state --state INVALID -j DROP

Viewing all articles
Browse latest Browse all 19115

Trending Articles