MASQUERADE and Grsecurity

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

MASQUERADE and Grsecurity

Postby alpmuniz » Sat Apr 12, 2008 1:58 pm

My system: Debian 4.0 2.6.23.14 / Grsecurity 2.1.11.2.6.23.9

Problem: Everething was ok with kernel 2.6.18.5. So i upgraded to 2.6.23.14 with grsecurity. I used the generic config (Grsecurity). This system is my router and run iptables with MASQUERADE. When I access from my station some Internet sites, the packets exchaged between the station and the sites's server suddenly stop. It doesnt happen with every sites. If the station try, for example, http://www.oglobo.com.br, we can see the problem (with tcpdump).
With Squid installed on this same system there is no problem. I turned to old kernel without Grsecurity and the problem went out.
alpmuniz
 
Posts: 1
Joined: Sat Apr 12, 2008 1:42 pm

Re: MASQUERADE and Grsecurity

Postby specs » Tue Apr 29, 2008 12:20 pm

If you have a problem, why do you change 2 things at once?

I know grsecurity with 2.6.18 is not an option, but there always is a big chance the vanilla kernel without grsecurity also won't work.
specs
 
Posts: 190
Joined: Sun Mar 26, 2006 7:00 am


Return to grsecurity support