Skip to content
  • Florian Westphal's avatar
    netfilter: conntrack: udp: only extend timeout to stream mode after 2s · d535c8a6
    Florian Westphal authored
    
    
    Currently DNS resolvers that send both A and AAAA queries from same source port
    can trigger stream mode prematurely, which results in non-early-evictable conntrack entry
    for three minutes, even though DNS requests are done in a few milliseconds.
    
    Add a two second grace period where we continue to use the ordinary
    30-second default timeout.  Its enough for DNS request/response traffic,
    even if two request/reply packets are involved.
    
    ASSURED is still set, else conntrack (and thus a possible
    NAT mapping ...) gets zapped too in case conntrack table runs full.
    
    Signed-off-by: default avatarFlorian Westphal <fw@strlen.de>
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    d535c8a6