OSPF needs connection tracking?

Hi,

I’d strange effects when I disable connection tracking on a
router which talks ospf to it’s neighbors. To some neighbors
he did not manage to build neighborhood?

Filtering allows all addresses within my network (input)
to talk to this router.

Any Idea?

Stefan

Did you take into account that OSPF does send
some packets to a Multicast destination address
in some situations? You’d need to allow these
packets to reach your router as well…


–Tom

Yes. I’ve an input rule which allows all packets from all ips on my network.
I sniffed and can see the Packets to 224.0.0.5 from the problem neighbor.
Source is an allowed ip.

Stefan