doc:appunti:linux:sa:nf_conntrack_expect
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| doc:appunti:linux:sa:nf_conntrack_expect [2025/01/10 12:56] – [Shorewall and helpers] niccolo | doc:appunti:linux:sa:nf_conntrack_expect [2025/06/09 09:57] (current) – [Shorewall and helpers] niccolo | ||
|---|---|---|---|
| Line 142: | Line 142: | ||
| </ | </ | ||
| - | And be more specific with helpers in **/ | + | And be more specific with helpers in **/ |
| < | < | ||
| + | HELPER | ||
| </ | </ | ||
| + | This combination will create the following iptable rule into the raw table: | ||
| + | |||
| + | < | ||
| + | Chain PREROUTING (policy ACCEPT 12 packets, 792 bytes) | ||
| + | pkts bytes target | ||
| + | 0 0 CT 17 | ||
| + | </ | ||
| + | |||
| + | The default **Debian 12 Bookworm** configuration for Shorewall provides a **conntrack** file where helpers can be enabled only if the Shorewall **AUTOHELPERS** option is enabled (in '' | ||
| + | |||
| + | For example you can enable the sip helper adding this line in **/ | ||
| + | |||
| + | < | ||
| + | CT: | ||
| + | </ | ||
| + | |||
| + | In this case the helper is instantiated into the raw table in both PREROUTING and OUTPUT chains. | ||
| + | |||
| + | ==== Shorewall upgrade from Debian 11 to 12 ==== | ||
| + | |||
| + | In Debian, upgrading to **Shorewall 5.2.8** as per upgrade from **Debian 11 Bullseye** to **Debian 12 Bookworm**, connection tracking protocol helpers are no longer globally enabled by default; use **shorewall-conntrack(5)** or **shorewall-rules(5)** to enable them as appropriate where they are required. | ||
| - | FIXME ... edit shorewall-conntrack or shorewall-rules. | + | Setting **AUTOHELPERS** to ' |
| ===== Web references ===== | ===== Web references ===== | ||
doc/appunti/linux/sa/nf_conntrack_expect.1736510218.txt.gz · Last modified: by niccolo
