Bug 10665 - kernel: nf_conntrack: message on every boot
Summary: kernel: nf_conntrack: message on every boot
Status: CLOSED FIXED
Alias: None
Product: IPFire
Classification: Unclassified
Component: --- (show other bugs)
Version: 2
Hardware: unspecified Unspecified
: - Unknown - - Unknown -
Assignee: Michael Tremer
QA Contact:
URL:
Keywords:
Depends on: 10844 10908
Blocks:
  Show dependency treegraph
 
Reported: 2014-10-31 15:00 UTC by Daniel Weismüller
Modified: 2016-04-23 00:07 UTC (History)
2 users (show)

See Also:


Attachments
archive which include the modified files (42.21 KB, application/gzip)
2016-01-07 14:11 UTC, Daniel Weismüller
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Weismüller 2014-10-31 15:00:09 UTC
On every boot the folowing kernel message apears.

"kernel:	nf_conntrack: automatic helper assignment is deprecated and it will be removed s oon. Use the iptables CT target to attach helpers instead."

Further informatios see here:
https://home.regit.org/netfilter-en/secure-use-of-helpers/
Comment 1 Michael Tremer 2015-04-22 18:13:04 UTC
Could you please apply this to your machine and check if it is working alright?

http://git.ipfire.org/?p=people/ms/ipfire-2.x.git;a=commitdiff;h=b1109b8af5f0a5e3ab7f0b68211d63ab0594c0ac
Comment 2 Daniel Weismüller 2015-05-11 15:23:02 UTC
After applying the patches there appears the following message in the kernel log.

kernel: 	xt_CT: No such helper "pptp"
Comment 3 Michael Tremer 2015-05-12 12:59:21 UTC
Note to self: maybe decrease the SIP timeout to 1800 seconds or even less
Comment 4 Tom Rymes 2015-12-15 20:53:05 UTC
FWIW, I am still seeing this behavior as of Core 95 today.

nf_conntrack: automatic helper assignment is deprecated and it will be removed soon. Use the iptables CT target to attach helpers instead.
Comment 5 Michael Tremer 2015-12-15 21:34:17 UTC
This is indeed not fixed as there is no feedback.
Comment 6 Daniel Weismüller 2016-01-07 14:11:28 UTC
Created attachment 397 [details]
archive which include the modified files

Please extract this archive to /

Following modified files are included:
/var/ipfire/langs/en.pl 
/srv/web/ipfire/cgi-bin/optionsfw.cgi 
/etc/rc.d/init.d/firewall 
/etc/modprobe.d/nf_conntrack.conf 

Please make a backup of the existing files before extracting the archive.
Comment 7 Daniel Weismüller 2016-01-07 14:32:33 UTC
To configure take a look at 
https://ipfire:444/cgi-bin/optionsfw.cgi