Search found 3 matches

by n8v8r
01 Jun 2018, 10:20
Forum: Suggestions (csf)
Topic: dns over tcp - invalid packets tcp_in port 853
Replies: 2
Views: 2033

Re: dns over tcp - invalid packets tcp_in port 853

It appears that CSF is flagging erroneously almost any traffic (in/out) over port 853 as invalid with having Drop out of order packets and packets in an INVALID state in iptables connection tracking enabled and set PS_PORTS = 0:65535,ICMP,INVALID,OPEN,BRD Not clear whether the root cause is iptables...
by n8v8r
21 Apr 2018, 22:16
Forum: Suggestions (csf)
Topic: nftables
Replies: 4
Views: 1871

nftables

Considering that nftables has been around a while and since then matured would it not be good to transition CSF accordingly? Supposedly it should make the life around netfilter easier

https://wiki.nftables.org/wiki-nftables ... ftables%3F
by n8v8r
21 Apr 2018, 22:06
Forum: Suggestions (csf)
Topic: dns over tcp - invalid packets tcp_in port 853
Replies: 2
Views: 2033

dns over tcp - invalid packets tcp_in port 853

Debian 9.4 server kernel 4.9.0-6-amd64 iptables ipv4 v1.6.0 unbound 1.6.0 csf 12.02 (DNS strict off / Paket Filter on) unbound, being the local resolver, is issuing DNS over TLS requests to the upstream resolver over TCP with destination port 853. The response from the upstream resolver is getting b...