Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #60977

Bug#895364: iptables: using conntrack prevents dropping ip fragments

From Jim Pirzyk <jpirzyk@opendns.com>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#895364: iptables: using conntrack prevents dropping ip fragments
Date 2018-05-11 21:40 +0200
Message-ID <vOm3v-399-5@gated-at.bofh.it> (permalink)
References <vD3nz-vm-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

This issue has been solved by using the 4.16 kernel (from debian-9
backports) and adding the following file (with contents):

cat /etc/modprobe.d/iptable_raw.conf
options iptable_raw raw_before_defrag=1

Back to linux.debian.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

Bug#895364: iptables: using conntrack prevents dropping ip fragments Jim Pirzyk <jpirzyk@opendns.com> - 2018-04-10 17:30 +0200
  Bug#895364: iptables: using conntrack prevents dropping ip fragments Jim Pirzyk <jpirzyk@opendns.com> - 2018-04-10 23:20 +0200
  Bug#895364: iptables: using conntrack prevents dropping ip fragments Jim Pirzyk <jpirzyk@opendns.com> - 2018-05-11 21:40 +0200

csiph-web