From mboxrd@z Thu Jan 1 00:00:00 1970 From: Arturo Borrero Gonzalez Subject: Re: conntracd init.d reload is broken on Centos6 Date: Sat, 18 Nov 2017 13:47:19 +0100 Message-ID: References: <20171116132528.GA2159@salvia> Mime-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Cc: Pablo Neira Ayuso , Netfilter Development Mailing list To: Jason Hendry Return-path: Received: from mail-wm0-f68.google.com ([74.125.82.68]:45373 "EHLO mail-wm0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S966495AbdKRMrm (ORCPT ); Sat, 18 Nov 2017 07:47:42 -0500 Received: by mail-wm0-f68.google.com with SMTP id 9so11001949wme.4 for ; Sat, 18 Nov 2017 04:47:41 -0800 (PST) Received: from mail-wm0-f43.google.com (mail-wm0-f43.google.com. [74.125.82.43]) by smtp.gmail.com with ESMTPSA id s6sm4501844edc.2.2017.11.18.04.47.40 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 18 Nov 2017 04:47:40 -0800 (PST) Received: by mail-wm0-f43.google.com with SMTP id 5so9867463wmk.1 for ; Sat, 18 Nov 2017 04:47:40 -0800 (PST) In-Reply-To: Sender: netfilter-devel-owner@vger.kernel.org List-ID: Please avoid top-posting. On 17 November 2017 at 23:55, Jason Hendry wrote: > Turns out sending conntrackd a -HUP signal causes it to die. I can not > find any documentation/reference on what signals conntrackd accepts, > is there one to tell it to reload its config? We are running > conntrackd 0.9.14 > That's a very old version of conntrackd (8+ years ago?). Please use a newer version. ATM conntrackd is unable to reload config. This is something I would like to improve in the future. > Can you also clarify the effect of restarting conntrackd, is it a safe > operation to do? Will it cause any interruption to connections? Will > it re-sync with the kernel state table? Will it re-sync with its peer? > Connections are in the kernel and those are not affected by conntrackd restart. Depending on your conntrackd config you may lose state updates which are in the conntrackd cache but not in the kernel yet. In newer versions of conntrackd there is a StartupResync option to request resync with other node at startup.