[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Iptables FW under 2.4.0-test11



>>>>> "SSA" == S Salman Ahmed <ssahmed@pathcom.com> writes:
    SSA>  What iptables config option causes this problem ? 
    SSA> 

To answer my own question, the CONFIG_IP_NF_CONNTRACK=y option is the
one that causes the problem. My firewall has to be setup as a
masquerdaing FW, and in 2.4.0 NAT cannot be used without this option
enabled. So I can't use NAT in 2.4.0 with this option disabled.

I tried the 2.4.0-test13-pre4 which is supposed to have the fix for this
netfilter bug, but "ping -s 65000 localhost" still locks my system
hard.

I have gone back to 2.2.18+ipchains until this netfilter problem is more
reliably solved. Thanks for the info Giacomo.

-- 
Salman Ahmed
ssahmed AT pathcom DOT com



Reply to: