Inetd suddenly stops accepting connections

scode@scode.ddns.org
Sun, 6 Jun 1999 21:00:42 +0200


--VS++wcV0S1rZb1Fb
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Hello,
=20
I have a problem with inetd. After installing the TIS FWTK on a fire wall,
I had inetd launch http-gw in response to connections on port 80. This wo=
rks
fine - for a while. It always stops accepting connections after a few min=
ut=3D
es.
Other services keep going (I tried enabled the echo server for example, a=
nd
after it stopped listening to 80 I could still connect to the echo server=
).
=20
Could it be some kind of built-in DOS attack protection or something? Or
possibly a bug? Any ideas?
=20
Here's the relevant part of the output of "netstat -a -n" when it *doesn'=
t*
work.
=20
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
tcp 290 0 10.0.0.1:80 10.0.0.10:1690 CLOSE
tcp 276 0 10.0.0.1:80 10.0.0.10:1576 CLOSE
=20
And here's when it *does* work:
=20
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 10.0.0.1:80 10.0.0.10:1705 CLOSE
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
tcp 290 0 10.0.0.1:80 10.0.0.10:1690 CLOSE
tcp 276 0 10.0.0.1:80 10.0.0.10:1576 CLOSE
=3D20
The firewall's IP is 10.0.0.1 and the computers trying to access it are
10.0.0.x (in this case 10.0.0.10 has been the test client).
=20
I must confess to not remembering the details of the TCP connection state=
s,
but why do a bunch of them linger around in the CLOSE state? And it seems=
to
be inetd is listening in both cases...
=20
Any help would be greatly appreciated.
=20
Thanks!
=20

/ Peter Schuller

---
PGP userID: 0x5584BD98 or 'Peter Schuller <scode@scode.ddns.org>'
E-Mail: scode@scode.ddns.org Web: http://hem.passagen.se/petersch
Help create a free Java based operating system - www.jos.org.

--VS++wcV0S1rZb1Fb Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE----- Version: PGPfreeware 5.0i for non-commercial use MessageID: VS1xW3B7jhLi3bFHX9PNMplIbjezCLf/

iQA/AwUBN1rFWcBfJ1FVhL2YEQIadQCeNSouEkZvTHJrNmhrnaXBQdq9gB0AoNEG tQ6aCwj4IN+q1I1VohnM4hdH =KES7 -----END PGP SIGNATURE-----

--VS++wcV0S1rZb1Fb-- - To unsubscribe from this list: send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.rutgers.edu