Skip to content

Conversation

@brada4
Copy link

@brada4 brada4 commented Feb 16, 2025

We cannot fix invalid (checksum, out of state, short) packets by replying them with valid packet. Lets keep grief to bare minimum.

Part-fixes: openwrt/openwrt#13340
(the "new" valid packets would have been replied with spoofed packet but those should have been relatively rare to make problem less noticeable)

Changes jump to goto - there is no "next" rule to reach after connection is reset and forgotten.

Signed-off-by: Andris PE neandris@gmail.com

We cannot fix invalid (checksum, out of state, short) packets by
replying them with valid packet. Lets keep grief to bare minimum
@brada4
Copy link
Author

brada4 commented Feb 16, 2025

@f00b4r0 tell me if i am wrong tyy

@brada4 brada4 changed the title Do not reject invalid (out of state) packets ruleset: do not reject invalid (out of state) packets May 19, 2025
@brada4
Copy link
Author

brada4 commented Jun 19, 2025

Alternative - provide this in nftables.d example but as active rule?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Firewall: Significang packet loss on WAN when using default rule "wan Forward reject", solution: "wan Forward drop"

1 participant