Re: Iptables FW under 2.4.0-test11
>>>>> "SSA" == S Salman Ahmed <ssahmed@pathcom.com> writes:
SSA> What iptables config option causes this problem ?
SSA>
To answer my own question, the CONFIG_IP_NF_CONNTRACK=y option is the
one that causes the problem. My firewall has to be setup as a
masquerdaing FW, and in 2.4.0 NAT cannot be used without this option
enabled. So I can't use NAT in 2.4.0 with this option disabled.
I tried the 2.4.0-test13-pre4 which is supposed to have the fix for this
netfilter bug, but "ping -s 65000 localhost" still locks my system
hard.
I have gone back to 2.2.18+ipchains until this netfilter problem is more
reliably solved. Thanks for the info Giacomo.
--
Salman Ahmed
ssahmed AT pathcom DOT com
Reply to: