User Tools

Site Tools


doc:appunti:linux:sa:nf_conntrack_expect

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
doc:appunti:linux:sa:nf_conntrack_expect [2025/01/10 12:25] – [Shorewall and helpers] niccolodoc:appunti:linux:sa:nf_conntrack_expect [2025/03/14 10:05] (current) – [Shorewall and helpers] niccolo
Line 135: Line 135:
 in this case helpers will be configured into the iptables raw table for ''tcp dpt:21'' (FTP) and ''udp dpt:5060'' (SIP). in this case helpers will be configured into the iptables raw table for ''tcp dpt:21'' (FTP) and ''udp dpt:5060'' (SIP).
  
-But the recommended configuration is the following:+But the **recommended** configuration is the following:
  
 <file> <file>
Line 142: Line 142:
 </file> </file>
  
-FIXME ... edit shorewall-conntrack or shorewall-rules.+And be more specific with helpers in **/etc/shorewall/rules**, e.g.
 + 
 +<file> 
 +HELPER    loc    -    udp    5060    ; helper=sip 
 +</file> 
 + 
 +This combination will create the following iptable rule into the raw table: 
 + 
 +<code> 
 +Chain PREROUTING (policy ACCEPT 12 packets, 792 bytes) 
 + pkts bytes target  prot opt in     out  source     destination   
 +    0     0 CT      17   --  lan0      0.0.0.0/ 0.0.0.0/   udp dpt:5060 CT helper sip 
 +</code> 
 + 
 +Or you can add this into **/etc/shorewall/conntrack**: 
 + 
 +<code> 
 +CT:helper:sip:PO 
 +</code> 
 + 
 +In this case the helper is instantiated into the raw table in both PREROUTING and OUTPUT chains. 
 + 
 +The default **Debian 12 Bookworm** configuration for Shorewall provides a **conntrack** file where helpers are enabled only if the Shorewall **AUTOHELPERS** option is enabled (in ''shorewall.conf'') and if the **CT_TARGET** iptables/netfilter capability is available (verify the output of ''shorewall show capabilities''). 
 + 
 +==== Shorewall upgrade from Debian 11 to 12 ==== 
 + 
 +In Debian, upgrading to **Shorewall 5.2.8** as per upgrade from **Debian 11 Bullseye** to **Debian 12 Bookworm**, connection tracking protocol helpers are no longer globally enabled by default; use **shorewall-conntrack(5)** or **shorewall-rules(5)** to enable them as appropriate where they are required. 
 + 
 +Setting **AUTOHELPERS** to 'Yes' in shorewall.conf restores the previous behavior.
  
 ===== Web references ===== ===== Web references =====
doc/appunti/linux/sa/nf_conntrack_expect.1736508339.txt.gz · Last modified: 2025/01/10 12:25 by niccolo