|
From: Philippe W. <phi...@ae...> - 2009-10-01 20:56:20
|
Serge Leschinsky a écrit : > Philippe Weill wrote: >> Hi everybody >> >> we are testing a new firewall with 1.4RC2 >> >> network is bonding + vlan >> routing is ospf >> >> if we load the iptable_nat module >> even without any nat and firewall rules >> >> ospf is not working anymore >> 2009/10/01 06:40:22 OSPF: Link State Acknowledgment: Neighbor[192.168.20.9] state Init is less than >> Exchange >> >> any idea what we could test ? > > Does tcpdump show normal OSPF negotiation? > > Serge > OK we found the problem first we had a problem with a nat rule at boot but as a side effect even when stopping firewall iptables -t nat -Lnv doesn't show any rules but bad nat continue with nf_conntrack (at least for 600 secondes ) root@sphinx:~ # more /proc/sys/net/netfilter/nf_conntrack_generic_timeout 600 removing nat module permit to ospf to work but reloading the module before waiting 10 minutes make the problem to restart thanks to have tried hope this could help somebody else -- Weill Philippe - Administrateur Systeme et Reseaux CNRS/UPMC/IPSL LATMOS (UMR 8190) |