All of lore.kernel.org
 help / color / mirror / Atom feed
* [RFC PATCH] Disabling helper assignement by default
@ 2012-03-26 22:05 Eric Leblond
  2012-03-26 22:05 ` [PATCH] conntrack: add /proc entry to disable helper " Eric Leblond
  0 siblings, 1 reply; 9+ messages in thread
From: Eric Leblond @ 2012-03-26 22:05 UTC (permalink / raw)
  To: pablo; +Cc: netfilter-devel

Hello,

Here's a patch which provides a way to disable helper assignement by
default To preserve backward compatibility, this feature is disabled
by default.

Once the feature is activated, the user has to manually define
the helper assignement by using the CT target.
This patch is aiming at improving the situation described in the
'Secure use of iptables and connection tracking helpers' document:
	https://home.regit.org/netfilter-en/secure-use-of-helpers/
where a ports=0 loading option was given to emulate this behaviour.

BR,
--
Eric Leblond <eric@regit.org>

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2012-04-19 18:11 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2012-03-26 22:05 [RFC PATCH] Disabling helper assignement by default Eric Leblond
2012-03-26 22:05 ` [PATCH] conntrack: add /proc entry to disable helper " Eric Leblond
2012-03-27 15:36   ` Pablo Neira Ayuso
2012-03-28  6:57     ` [PATCH v2] " Eric Leblond
2012-03-28 13:19       ` rework of patch following git rebase Eric Leblond
2012-03-28 13:19         ` [PATCH v2.1] conntrack: add /proc entry to disable helper by default Eric Leblond
2012-04-12 15:26           ` Pablo Neira Ayuso
2012-04-12 16:06             ` Eric Leblond
2012-04-19 18:11               ` Pablo Neira Ayuso

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.