From mboxrd@z Thu Jan 1 00:00:00 1970 From: Florian Westphal Subject: Re: nftables and connection tracking Date: Sun, 21 Jun 2020 12:45:16 +0200 Message-ID: <20200621104516.GM26990@breakpoint.cc> References: <20200621080614.GK26990@breakpoint.cc> <20200621090142.GL26990@breakpoint.cc> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: Content-Disposition: inline In-Reply-To: Sender: netfilter-owner@vger.kernel.org List-ID: Content-Type: text/plain; charset="iso-8859-1" To: Marek =?iso-8859-15?Q?Gre=A8ko?= Cc: netfilter@vger.kernel.org Marek Gre=A8ko wrote: > Hello, >=20 > unfortunately the helper is not there: >=20 > conntrack -L | grep sip -> no output >=20 > It is strange, that if I use iptables-nft it is working. Some userspace p= roblem? No, looks more like a kernel bug to me, I will have a look on Monday. In mean time, you can work around this bug by removing the entire "ip raw" / "ct set" stuff. and then use: sysctl net.netfilter.nf_conntrack_helper=3D1 to re-enable the old auto-assign behaviour.