Re: nftables and connection tracking

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Marek Greško <mgresko8@xxxxxxxxx> wrote:
> Hello,
> 
> unfortunately the helper is not there:
> 
> conntrack -L | grep sip                     -> no output
> 
> It is strange, that if I use iptables-nft it is working. Some userspace problem?

No, looks more like a kernel bug to me, I will have a look on
Monday.

In mean time, you can work around this bug by removing the entire "ip
raw" / "ct set" stuff.

and then use:
sysctl net.netfilter.nf_conntrack_helper=1

to re-enable the old auto-assign behaviour.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux