The problem goes away with the patches you mentioned. I also tried to establish a connection from a NATed box behind The linux firewall to an external PPTP server ( win2k and linux poptop) : it works , even without the module loaded . I think at this point I miss the functionality of the pptp_conntrack module ? When is it necessary to load it ? - Enrico > -----Original Message----- > From: Philip Craig [mailto:philipc@xxxxxxxxxxxx] > Sent: venerdì 12 settembre 2003 2.37 > To: Enrico Demarin > Cc: netfilter@xxxxxxxxxxxxxxxxxxx > Subject: Re: Conntrack PPTP broken in 2.4.22 ? > > > Enrico Demarin wrote: > > I have tried to use the pptp_conntrack patch from the last > > patch-o-matic on Linux kernel 2.4.22 , but with that patch applied, > > apps using > > > > getsockopt SO_ORIGINAL_DST stop working : > > > > the perror i get is : > > > > getsockopt(SO_ORIGINAL_DST): No such file or directory > > The following patch in the netfilter patch-o-matic CVS is > meant to fix this: > http://cvs.netfilter.org/~checkout~/netfilter/patch-o-matic/pending/63_g etorigdst-tuple-zero.patch?sortby=rev But unfortunately that patch is broken too, and you'll need to apply the patch from this message to fix the patch: http://lists.netfilter.org/pipermail/netfilter-devel/2003-September/0123 82.html (Btw, check the netfilter-devel archives for this month for some discussion about what patches you need for pptp conntrack.) -- Philip Craig - philipc@xxxxxxxxxxxx - http://www.SnapGear.com SnapGear - Custom Embedded Solutions and Security Appliances