[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#895364: iptables: using conntrack prevents dropping ip fragments



This issue has been solved by using the 4.16 kernel (from debian-9 backports) and adding the following file (with contents):

cat /etc/modprobe.d/iptable_raw.conf
options iptable_raw raw_before_defrag=1

Reply to: