Re: Restrictive FTP egress using conntrack helper

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Pablo,

On Sun, Feb 12, 2017 at 03:19:40PM +0100, Pablo Neira Ayuso wrote:

> > What's bugging me is that I still don't see an expectation being
> > created with conntrack -L expect.
> It's very unlikely to see FTP expectation via conntrack -L since they
> are created and destroyed very quickly if you are testing with a FTP
> client.

I thought so as well and tried to catch it using a while [ 1 ] loop ...

> So `conntrack -E expect' is likely a better option for the debugging
> purposes you need.

... but conntrack -E expect shows it plain as day of course. Thank you!
-- 
Michael
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux