On Wed, Aug 09, 2017 at 01:06:54PM +0200, Eric Leblond wrote: > Hello, > > On Wed, 2017-08-09 at 12:36 +0200, Marc Neudorfer wrote: > > Hello, > > > > i am currently using Debian 9 (nft 0.7, kernel 4.9). > > I tried to use nft as primary firewall for my network, but there are > > a > > lot of problems with our sip/voip phones (phones are ringing, no > > voice > > -> ct-problem) > > The wiki says, the ct-helpers are only available with nft 0.8 and > > kernel > > 4.12. > > Is there any known method to get sip-phones to work with nft 0.7? Or > > some kind of workaround? > > Indeed, connection tracking helpers assignation can only be used with > nft 0.8 and Linux 4.12. > > You can set automatic assignement with: > echo 1 > /proc/sys/net/netfilter/nf_conntrack_helper > > BR > -- > Eric Leblond <eric@xxxxxxxxx> > Blog: https://home.regit.org/ Hi Eric, Where is nft 0.8? I just built the latest git pulls og nfatbles and libnftnl but nft still identifies as 0.7. Cheers ... Duncan. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html