Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 6894 - iptables 1.2.7 -p icmp misbehaviour
Summary: iptables 1.2.7 -p icmp misbehaviour
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Core system (show other bugs)
Hardware: x86 Linux
: High major (vote)
Assignee: Daniel Ahlberg (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2002-08-22 15:19 UTC by Ronald Moesbergen
Modified: 2003-02-04 19:42 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
iptables-1.2.7 icmp patch (iptables-1.2.7-patch.txt,5.62 KB, patch)
2002-08-22 15:19 UTC, Ronald Moesbergen
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Ronald Moesbergen 2002-08-22 15:19:04 UTC
Hi,

With iptables 1.2.7 if you specify -p icmp -j ACCEPT, no icmp traffic is 
allowed through. If you list the rules with iptables -L you'll see that only 
icmp type 'echo-reply' is allowed and all other icmp traffic is blocked. I've 
seached the netfilter mailing list and found a patch for this problem. Can 
someone add this patch to the ebuild?

Thanks,
Ronald.
Comment 1 Ronald Moesbergen 2002-08-22 15:19:40 UTC
Created attachment 3316 [details, diff]
iptables-1.2.7 icmp patch
Comment 2 Daniel Ahlberg (RETIRED) gentoo-dev 2002-08-25 12:56:49 UTC
I have masked iptables-1.2.7 as it contains bugs confirmed by the authors of
iptables. A new version, 1.2.7a, is to be released ASAP. I will repoen these
bugs and make sure the errors reported doesn't exist in the new version before
unmasking 1.2.7a.
Comment 3 Daniel Ahlberg (RETIRED) gentoo-dev 2002-08-27 01:49:44 UTC
I've just commited iptables 1.2.7a. Please test this version and see if upstream
has fixed your problems. It's currently masked, I need to know if this version
works as expected before I can unmask.
Comment 4 Ronald Moesbergen 2002-08-27 15:26:05 UTC
I've checked the new version and it has solved the problem. Works great now! 
 
Thanks, 
Ronald.