Why does iptables/netfilter randomly seem to not accept packets?

Solution Verified - Updated -

Issue

  • When using iptables, the front-end to the netfilter module, it appears as if a random packet is seen in a packet capture but it never makes it to the application.
  • When viewing this in a packet capture, sometimes an ICMP "Host Prohibited" packet is seen immediately after.
  • iptables receiving and rejecting INVALID packets

Environment

  • Red Hat Enterprise Linux
  • iptables firewall with connection tracking (including firewalld)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.