Re: nf_conntrack_sip regression?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Le 09/10/2016 à 11:27, Joerg Dorchain a écrit :
> On Sun, Oct 09, 2016 at 05:55:18AM +0200, Adel Belhouane wrote:
>> Le 09/10/2016 à 02:19, Joerg Dorchain a écrit :

> I am sorry to quote myself, but as I wrote, I have in the RAW
> table
> 
>> Chain PREROUTING (policy ACCEPT 19781 packets, 3776K bytes)
>>  pkts bytes target     prot opt in     out     source               destination
>>    86 48515 CT         udp  --  any    any     anywhere             anywhere             udp dpt:sip CT helper sip
> 

Well sorry for the previous answer made without thinking (or reading), but indeed
I can read iptables-save better than iptables -L.

If it's really a change in the sip helper code, sorry I can't help and I
hope somebody else will help you.

Else, if your ppp0's MTU is a bit low, SIP might switch from UDP to
TCP (RFC3261 18.1.1), then adding a second CT rule with tcp port 5060
would handle it.

> 
> Thanks for bearing with me,
> 
> Joerg
> 

Adel
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux