Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #79639
| From | Hauke Fath <hf@spg.tu-darmstadt.de> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts |
| Date | 2023-07-18 12:40 +0200 |
| Message-ID | <GSQhz-145h-9@gated-at.bofh.it> (permalink) |
| References | (3 earlier) <GSevD-GCQ-3@gated-at.bofh.it> <GSqGt-NYJ-1@gated-at.bofh.it> <GSBix-UDB-3@gated-at.bofh.it> <GNRnX-2WoE-3@gated-at.bofh.it> <GSBix-UDB-3@gated-at.bofh.it> |
| Organization | TU Darmstadt, Nachrichtentechnik |
Cross-posted to 2 groups.
On 7/17/23 20:29, Ben Hutchings wrote:
>> But the router's package filter will have lost state after a reboot,
>> and reject packets from tcp connections that the clients assume to
>> exist. This is not a problem with udp, because connection-less.
>
> Ah, I see. You didn't mention that there was dynamic NAT involved
> before.
Because it isn't. What is involved is a stateful packet filter (FreeBSD
pf). I said
| We run nfs through a router (several client subnets accessing servers
| in an internal server subnet), and found nfs over udp a lot more
| robust in the face or router reboots.
> If an NFS server is rebooted abruptly (so it doesn't properly close TCP
> connections), once it's back up it will respond to any requests from
> clients with a TCP RST, and they should reconnect.
Understood, and not relevant here.
> If a NAT router between client and server is rebooted, I think that
> something similar should happen, but the router would need to send the
> TCP RST instead.
After a router reboot, the stateful packet filter will have lost
information on active tcp connections, and (rightfully) reject packets
for what the nfs clients (rightfully) see as an existing connection.
> Is your router configured to send a TCP RST when receiving a packet for
> an unknown connection, or does it just drop those packets? (In
> iptables this is the difference between REJECT and DROP policies.)
The router defaults to returning RST.
Anyway: I am not asking for an udp default here, but simply for Debian
to keep providing the _option_, and leave the decision to me, the admin.
Cheerio,
Hauke
--
The ASCII Ribbon Campaign Hauke Fath
() No HTML/RTF in email Institut für Nachrichtentechnik
/\ No Word docs in email TU Darmstadt
Respect for open standards Ruf +49-6151-16-21344
Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts Hauke Fath <hf@spg.tu-darmstadt.de> - 2023-07-04 18:50 +0200
Processed: Re: Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts "Debian Bug Tracking System" <owner@bugs.debian.org> - 2023-07-05 10:30 +0200
Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts Bastian Blank <waldi@debian.org> - 2023-07-05 10:30 +0200
Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts Hauke Fath <hf@spg.tu-darmstadt.de> - 2023-07-05 15:40 +0200
Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts Ben Hutchings <ben@decadent.org.uk> - 2023-07-16 20:20 +0200
Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts Hauke Fath <hf@spg.tu-darmstadt.de> - 2023-07-17 09:20 +0200
Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts Ben Hutchings <ben@decadent.org.uk> - 2023-07-17 20:40 +0200
Bug#1040343: linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts Hauke Fath <hf@spg.tu-darmstadt.de> - 2023-07-18 12:40 +0200
Bug#1040343: marked as done (linux-image-5.10.0-9-amd64: Kernel silenty de-supported nfsv3 UDP mounts) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2023-07-05 14:40 +0200
csiph-web