Tcp Spurious retransmissions after modification via netfilter hook

Viewed 244

I used a small python script(from github) to test netfilter hooks and used scapy for sniffing packets.

You can check the script on below link https://gist.github.com/eXenon/85a3eab09fefbb3bee5d#file-scapy_bridge-py

The script modifies payload length and checksum at tcp and ip layers before relaying it but it also causes Spurious transmission when checked in wireshark.

Can someone help me figure out the reason for Spurious retransmission in this case?

1 Answers

The answer lies within the following comment Howto intercept tcp packet and modify in the fly?. It is the kernel that detects the packet alteration and treats it as a packet loss. Therefore, it's more suitable/easier to use your script as a transparent proxy rather than doing tweaks at kernel level.

Related