[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20240716122241.200224-1-renmingshuai@huawei.com>
Date: Tue, 16 Jul 2024 20:22:41 +0800
From: renmingshuai <renmingshuai@...wei.com>
To: <pablo@...filter.org>, <kadlec@...ckhole.kfki.hu>, <fw@...len.de>,
<davem@...emloft.net>, <netfilter-devel@...r.kernel.org>,
<coreteam@...filter.org>, <netdev@...r.kernel.org>,
<linux-kernel@...r.kernel.org>
CC: <renmingshuai@...wei.com>, <yanan@...wei.com>, <qiangxiaojun@...wei.com>,
<mengkanglai2@...wei.com>, <caowangbao@...wei.com>,
<chentongbiao@...wei.com>, <tanqi8@...wei.com>
Subject: Are there Any Side Effects when net.netfilter.nf_conntrack_tcp_be_liberal is set to 1?
Hello, everyone:
I want to consult a sysctl option net.netfilter.nf_conntrack_tcp_be_liberal.
Commit fb366fc7541a ("netfilter: conntrack: correct window scaling with
retransmitted SYN") fix bug that results in packets incorrectly being marked
invalid for being out-of-window. I encountered this bug, and i found set
net.netfilter.nf_conntrack_tcp_be_liberal is to 1 also can solve this problem.
I want to enable nf_conntrack_tcp_be_liberal=1 but i don't know the side effects
of this sysctl option, for example if this will cause some network security problem.
If there are any other impacts, please let me know as well.
thanks.
Powered by blists - more mailing lists