Re: Linux 2.4.18 Kernel Panics related to Netfilter/iptables

glynis@butterfly.hjsoft.com
Tue, 3 Sep 2002 00:15:30 -0400


--mxv5cy4qt+RJ9ypb
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, Sep 02, 2002 at 10:21:56AM +0200, mk@fashaf.co.za wrote:
> One of my machines running kernel 2.4.18 is getting kernel panics=20
intermittently (30minutes to 4/5 hours).=20
> from the logs I believe is the culprit:
> kernel: LIST_DELETE: ip_conntrack_core.c:165=20
`&ct->tuplehash[IP_CT_DIR_REPLY]'(c6c78e44) not in &ip_conntrack_hash=20
[hash_conntrack(&ct->tuplehash[IP_CT_DIR_REPLY].tuple)].

i've wrestled quite a bit with this problem, but never really could
figure out the correct answers. some people blamed the compiler, but
different versions of the compiler still produced it.

i saw it in 2.4.18 and 2.4.19pre kernels on my dual athlon.

in the end i found switching from snat to masqerading for my internal
network seemed to eliminate it. also i found that if i eliminated my
udp outgoing remote log stream from syslog-ng, i could keep the snat
and have the box still live.

i'm now running nicely with 2.4.19, snat firewall rules, and no remote
logging.

--=20
____________________}John Flinchbaugh{______________________
| glynis@hjsoft.com http://www.hjsoft.com/~glynis/ |
~~Powered by Linux: Reboots are for hardware upgrades only~~

--mxv5cy4qt+RJ9ypb
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9dDdiCGPRljI8080RAqHBAJwPmtuIppWLqU0OO7NZpvrzrepiXwCffYTB
/JcQMvsdCkPLVV0XTjQdPbw=
=rUUn
-----END PGP SIGNATURE-----

--mxv5cy4qt+RJ9ypb--
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/