<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Firewall on The Gnu Pit</title><link>https://gnupit.net/firewall/</link><description>Recent content in Firewall on The Gnu Pit</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Thu, 21 Dec 2017 22:26:24 -0500</lastBuildDate><atom:link href="https://gnupit.net/firewall/index.xml" rel="self" type="application/rss+xml"/><item><title>Deprecated nf_conntrack automatic helper assignment</title><link>https://gnupit.net/posts/nf_conntrack/</link><pubDate>Thu, 21 Dec 2017 22:26:24 -0500</pubDate><guid>https://gnupit.net/posts/nf_conntrack/</guid><description>&lt;p&gt;For quite a while, I&amp;rsquo;ve been getting the &amp;ldquo;nf_conntrack: automatic helper assignment is deprecated and it will be removed soon&amp;rdquo; warning at boot. So I can&amp;rsquo;t say I was too surprised when I started getting &amp;ldquo;kernel: nf_conntrack: default automatic helper assignment has been turned off for security reasons and CT-based  firewall rule not found. Use the iptables CT target to attach helpers instead.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Back in January/February 2017 there was a &lt;a href="http://lkml.iu.edu/hypermail/linux/kernel/1702.0/00470.html"&gt;post&lt;/a&gt; on the Linux-Kernel mailing list submitting a patch to print out the warning so firewall admins would at least have notice. As best as I can tell from reading a ton of stuff, the warning is logged if a packet which would have otherwise traversed your firewall didn&amp;rsquo;t because there was no helper available. More information can be found at &lt;a href="https://home.regit.org/netfilter-en/secure-use-of-helpers/"&gt;Secure use of iptables and connection tracking helpers&lt;/a&gt;.&lt;/p&gt;</description></item></channel></rss>