Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Conntrack turns a blind eye to dropped SYNs

Blog post from Cloudflare

Post Details
Company
Date Published
Author
Jakub Sitnicki
Word Count
2,920
Company Posts That Month
48
Language
English
Hacker News Points
15
Post removed?
No
Summary

The text discusses the connection tracking layer in the Linux kernel called conntrack, and how it interacts with the network stack. It explains that conntrack relies on the Netfilter framework to get notified about network packets passing through the stack, and uses its set of hooks baked into the stack. The author also explores how to observe a TCP SYN packet dropped by the firewall using conntrack. They delve into various ways to discover the inner workings of the Linux network stack, such as using tools like drgn, bpftrace, or Ftrace, and cross-referencing source code.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 6 362 110 31 -35%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.