netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* state match incompatibilty across versions
@ 2013-08-06 18:23 Laurence J. Lane
  2013-08-06 20:35 ` Laurence J. Lane
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Laurence J. Lane @ 2013-08-06 18:23 UTC (permalink / raw)
  To: netfilter-devel

Debian Bug#718810 reports a problem with the state match across
iptables versions. The following rules were created with the same
states using 1.4.14. The state information on the state match do now
show with 1.4.19.1's iptables-save or " iptables -L". The conntrack
match's ctstate works as expected with the upgrade.

  # Generated by iptables-save v1.4.19.1 on Tue Aug  6 18:15:36 2013
  *filter
  :INPUT ACCEPT [270:16468]
  :FORWARD ACCEPT [0:0]
  :OUTPUT ACCEPT [197:23360]
  -A INPUT -m state
  -A INPUT -m conntrack --ctstate INVALID,NEW,RELATED,ESTABLISHED
  COMMIT
  # Completed on Tue Aug  6 18:15:36 2013

  # Generated by iptables-save v1.4.14 on Tue Aug  6 18:16:43 2013
  *filter
  :INPUT ACCEPT [535:33200]
  :FORWARD ACCEPT [0:0]
  :OUTPUT ACCEPT [384:42988]
  -A INPUT -m state --state INVALID,NEW,RELATED,ESTABLISHED
  -A INPUT -m conntrack --ctstate INVALID,NEW,RELATED,ESTABLISHED
  COMMIT
  # Completed on Tue Aug  6 18:16:43 2013

It seems to work fine the other way around, with 1.4.19.1 creating the rules.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2013-08-08 13:54 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-08-06 18:23 state match incompatibilty across versions Laurence J. Lane
2013-08-06 20:35 ` Laurence J. Lane
2013-08-06 22:33 ` Phil Oester
2013-08-08  1:28 ` Laurence J. Lane
2013-08-08  4:32   ` Phil Oester
2013-08-08 13:53     ` Laurence J. Lane

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).