All of lore.kernel.org
 help / color / mirror / Atom feed
* NFQUEUE/iptables and kernel warning messages for net/ipv4/tcp_output.c
@ 2020-02-17 17:30 Vieri Di Paola
  2020-02-18 12:39 ` Florian Westphal
  0 siblings, 1 reply; 5+ messages in thread
From: Vieri Di Paola @ 2020-02-17 17:30 UTC (permalink / raw)
  To: netfilter

Hi,

Whenever I use NFQUEUE/iptables to send traffic to an IDS/IPS (eg.
Suricata), I get an ugly kernel warning which can sometimes and on the
long run turn into a system freeze.

I'm using NFQUEUE 0:5, and I'm running Suricata with -q 0 -q 1 -q 2 -q
3 -q 4 -q 5 as arguments.

I've already reported the issue on the LKML here:

https://lkml.org/lkml/2020/2/13/1255

However, I've been told by the Suricata ML to try and post here too.

The message "WARNING: CPU: * at net/ipv4/tcp_output.c:915" does not
appear when I stop using Suricata with NFQUEUE.

Regards,

Vieri

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2020-02-19 19:37 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-02-17 17:30 NFQUEUE/iptables and kernel warning messages for net/ipv4/tcp_output.c Vieri Di Paola
2020-02-18 12:39 ` Florian Westphal
2020-02-18 12:59   ` Vieri Di Paola
2020-02-18 13:21     ` Florian Westphal
2020-02-19 19:37       ` Vieri Di Paola

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.