Community discussions

MikroTik App
 
User avatar
BrianHiggins
Forum Veteran
Forum Veteran
Topic Author
Posts: 702
Joined: Mon Jan 16, 2006 6:07 am
Location: Norwalk, CT
Contact:

Connection tracking with BGP?

Thu Jun 04, 2009 5:27 am

I have two BGP routers, with one upstream BGP peer each. Since it is possible for connections to go out one router, and the return packets come in the other router, should I be disableing connection tracking on the routers?
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Connection tracking with BGP?

Thu Jun 04, 2009 6:27 am

yes.
 
User avatar
BrianHiggins
Forum Veteran
Forum Veteran
Topic Author
Posts: 702
Joined: Mon Jan 16, 2006 6:07 am
Location: Norwalk, CT
Contact:

Re: Connection tracking with BGP?

Thu Jun 04, 2009 7:08 pm

that's what I was thought, thanks for confirming.
 
sten
Forum Veteran
Forum Veteran
Posts: 919
Joined: Tue Jun 01, 2004 12:10 pm

Re: Connection tracking with BGP?

Thu Oct 01, 2009 8:01 pm

Why is this necessary?
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Connection tracking with BGP?

Thu Oct 01, 2009 9:18 pm

If the SYN packet comes in one router, gets put into the connection tracking on one router, and then leaves the other router, the first router won't see a complete connection and will start blocking things on the next inbound packets. Now you also have an outbound connection (reply) on the second router that looks new, but didn't start with a SYN packet. It's possible you could work around it by putting some rules in that just allowed everything, but that's not ideal and could get messy or complex when you need something else to work.

Who is online

Users browsing this forum: vetal12311 and 75 guests