Florian Westphal d535c8a69c netfilter: conntrack: udp: only extend timeout to stream mode after 2s
Currently DNS resolvers that send both A and AAAA queries from same source port
can trigger stream mode prematurely, which results in non-early-evictable conntrack entry
for three minutes, even though DNS requests are done in a few milliseconds.

Add a two second grace period where we continue to use the ordinary
30-second default timeout.  Its enough for DNS request/response traffic,
even if two request/reply packets are involved.

ASSURED is still set, else conntrack (and thus a possible
NAT mapping ...) gets zapped too in case conntrack table runs full.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
2018-12-21 00:48:38 +01:00
..
2018-11-08 20:45:04 -08:00
2018-10-23 10:57:06 -07:00
2018-07-24 14:10:42 -07:00
2018-11-08 20:45:04 -08:00
2018-11-10 16:55:11 -08:00
2018-08-13 20:45:49 -07:00
2018-10-22 19:59:20 -07:00
2018-11-04 08:20:09 -08:00
2018-07-24 14:10:42 -07:00
2018-07-24 14:10:42 -07:00