Community discussions

MikroTik App
用户头像
BrianHiggins
Long time Member
Long time Member
Topic Author
Posts: 689
加入: Mon Jan 16, 2006 6:07 am
Location:Norwalk, CT
Contact:

Connection tracking with BGP?

Thu Jun 04, 2009 5:27 am

I have two BGP routers, with one upstream BGP peer each. Since it is possible for connections to go out one router, and the return packets come in the other router, should I be disableing connection tracking on the routers?
Top
changeip
Forum Guru
Forum Guru
Posts: 3828
加入: Fri May 28, 2004 5:22 pm

Re: Connection tracking with BGP?

Thu Jun 04, 2009 6:27 am

yes.
Top
用户头像
BrianHiggins
Long time Member
Long time Member
Topic Author
Posts: 689
加入: Mon Jan 16, 2006 6:07 am
Location:Norwalk, CT
Contact:

Re: Connection tracking with BGP?

Thu Jun 04, 2009 7:08 pm

that's what I was thought, thanks for confirming.
Top
sten
Forum Veteran
Forum Veteran
Posts: 919
加入: Tue Jun 01, 2004 12:10 pm

Re: Connection tracking with BGP?

Thu Oct 01, 2009 8:01 pm

Why is this necessary?
Top
changeip
Forum Guru
Forum Guru
Posts: 3828
加入: Fri May 28, 2004 5:22 pm

Re: Connection tracking with BGP?

Thu Oct 01, 2009 9:18 pm

If the SYN packet comes in one router, gets put into the connection tracking on one router, and then leaves the other router, the first router won't see a complete connection and will start blocking things on the next inbound packets. Now you also have an outbound connection (reply) on the second router that looks new, but didn't start with a SYN packet. It's possible you could work around it by putting some rules in that just allowed everything, but that's not ideal and could get messy or complex when you need something else to work.
Top

Who is online

Users browsing this forum: No registered users and 2 guests