Bug 78842

Summary: RFE: Please enable filter support in pppd
Product: [Fedora] Fedora Reporter: Bernd Bartmann <bernd.bartmann>
Component: pppAssignee: Thomas Woerner <twoerner>
Status: CLOSED RAWHIDE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: dgunchev, mitr
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2004-08-17 09:17:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Bernd Bartmann 2002-12-01 23:27:42 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.0.1) Gecko/20021003

Description of problem:
The active-filter option in pppd does not work because filter support is not
enabled by default. This option is required for correct idle timeout hangup
behaviour. Right now pppd resets packet idle time counters for both incoming and
outgoing packets. This is problematic for users with dynamic IPs. Incoming
packets from unwanted services like file sharing servers (e.g Gnutella) reset
the idle time counter so pppd never kills the connection. This is not good for
users who pay for their online time. Setting up firewall rules does not help
because the firewall rules are checked after pppd handed the packet over to the
kernel.
The solution is to enable the filter service in pppd. With filtering enabled you
can use the option active-filter to setup special rules for the idle timeout
counters.
You only have to enable the variable FILTER=y in pppd/Makefile.linux. The option
requires a kernel with CONFIG_PPP_FILTER=y, but all current Red Hat kernels
already have this option enabled. Besides this libpcap is required. This problem
also applies to all earlier Red Hat versions 7.3, 7.2...


Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1. set an idle timeout for a ppp connection
2. the ppp connection is never killed when packets come IN 
3.
	

Additional info:

Comment 1 Bernd Bartmann 2003-07-30 16:01:43 UTC
Still no comment from Red Hat on this issue.

Comment 2 Bernd Bartmann 2004-02-13 20:03:47 UTC
We're now at FC2 Test1 and this bug is still at state NEW.

Comment 3 Ulrich Seidl 2004-06-14 14:18:31 UTC
Still unresolved?

Comment 4 Thomas Woerner 2004-08-17 09:17:42 UTC
Fixed in FC2 in rpm ppp-2.4.2-1 or newer.