From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Marc Haber <mh+netfilter@zugschlus.de>
Cc: netfilter@vger.kernel.org
Subject: Re: conntrack helpers in kernel 4.7
Date: Thu, 11 Aug 2016 13:34:35 +0200 [thread overview]
Message-ID: <20160811113435.GA4544@salvia> (raw)
In-Reply-To: <20160811085251.GR9430@torres.zugschlus.de>
On Thu, Aug 11, 2016 at 10:52:51AM +0200, Marc Haber wrote:
> Hi,
>
> I am running my firewall at home with Debian stable (which has
> iptables 1.4.21) with a current kernel. Since the update to kernel
> 4.7, my connection tracking seems to be broken which shows itself in
> sporadic malfunctions of SIP telephony. Protocols not needing
> conntrack helpers do still work fine.
>
> I have found the document "Secure use of iptables and connection
> tracking helpers" on
> https://home.regit.org/netfilter-en/secure-use-of-helpers/ and am
> currently suspecting that support for the legacy mechanisms has been
> removed in kernel 4.7 since the reject log messages for SIP packets
> have started after I upgraded to linux 4.7.
You can still recover the old automagic behaviour by:
echo 1 > /proc/sys/net/netfilter/nf_conntrack_helper
But that will go away too at some point given this behaviour is
unsecure as the document above describes, so please don't give up on
upgrading your ruleset.
[...]
> This confuses me:
>
> (1) Why does the packet end up in the input queue in the first place?
> To me, this looks like the incoming packet on unt381 is not correctly
> tracked by the NAT code. It should be natted and processed by the
> FORWARD chain.
>
> (2) Why are the packet counters of all ctstate rules with helper match
> "sip" at zero? Why don't they apply for the incoming packet which
> seems to fall through until the concluding REJECT rule?
Because no conntrack entries are getting the sip helper attached.
> (3) do I need the PREROUTING --jump CT rule mentioned in the Securing
> helpers page if I only use the default Port 5060?
Yes, the CT target explicitly attach the conntrack helper, so you
need something like:
-A PREROUTING -t raw -p udp --dport 5060 -j CT --helper sip
This plugs the sip helper to every new flow going to port 5060.
next prev parent reply other threads:[~2016-08-11 11:34 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-08-11 8:52 conntrack helpers in kernel 4.7 Marc Haber
2016-08-11 11:34 ` Pablo Neira Ayuso [this message]
2016-08-11 11:53 ` Marc Haber
2016-08-11 12:17 ` Pablo Neira Ayuso
2016-08-11 13:29 ` Marc Haber
2016-08-11 19:44 ` Marc Haber
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160811113435.GA4544@salvia \
--to=pablo@netfilter.org \
--cc=mh+netfilter@zugschlus.de \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.