User Tools

Site Tools


doc:appunti:linux:sa:nf_conntrack_expect

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
doc:appunti:linux:sa:nf_conntrack_expect [2025/01/10 14:44] – [Shorewall and helpers] niccolodoc:appunti:linux:sa:nf_conntrack_expect [2025/03/14 10:05] (current) – [Shorewall and helpers] niccolo
Line 148: Line 148:
 </file> </file>
  
-or you can add this into **/etc/shorewall/conntrack**:+This combination will create the following iptable rule into the raw table:
  
 <code> <code>
 +Chain PREROUTING (policy ACCEPT 12 packets, 792 bytes)
 + pkts bytes target  prot opt in     out  source     destination  
 +    0     0 CT      17   --  lan0      0.0.0.0/ 0.0.0.0/   udp dpt:5060 CT helper sip
 </code> </code>
  
 +Or you can add this into **/etc/shorewall/conntrack**:
  
-FIXME ... edit shorewall-conntrack or shorewall-rules.+<code> 
 +CT:helper:sip:PO 
 +</code> 
 + 
 +In this case the helper is instantiated into the raw table in both PREROUTING and OUTPUT chains. 
 + 
 +The default **Debian 12 Bookworm** configuration for Shorewall provides a **conntrack** file where helpers are enabled only if the Shorewall **AUTOHELPERS** option is enabled (in ''shorewall.conf'') and if the **CT_TARGET** iptables/netfilter capability is available (verify the output of ''shorewall show capabilities''). 
 + 
 +==== Shorewall upgrade from Debian 11 to 12 ==== 
 + 
 +In Debian, upgrading to **Shorewall 5.2.8** as per upgrade from **Debian 11 Bullseye** to **Debian 12 Bookworm**, connection tracking protocol helpers are no longer globally enabled by default; use **shorewall-conntrack(5)** or **shorewall-rules(5)** to enable them as appropriate where they are required. 
 + 
 +Setting **AUTOHELPERS** to 'Yes' in shorewall.conf restores the previous behavior.
  
 ===== Web references ===== ===== Web references =====
doc/appunti/linux/sa/nf_conntrack_expect.1736516690.txt.gz · Last modified: 2025/01/10 14:44 by niccolo