Wed May 11, 2005 12:33 pm
If filter table used (at least one rule active in any filter chain), but connection tracking is off, ANY fragmented IP packets on input or forward directions are lost with send back ICMP message "time for packet reassembly exceeded". (Simplyest test - ping RC1 box from workstation with packet size>1472). When connection tracking is on, or filter table unused, all fragmented IP packets accepted or forwarded correctly. On stable version 2.8 fragmented packets supported correctly without correllation with connection tracker.
If this is not bug, but real specific of firewall, ithis trick must be documented in details.