On Tue, Jul 12, 2016 at 09:24:26PM +0200, Dominic Hargreaves wrote: > On Sat, Jul 02, 2016 at 03:42:54PM -0400, Roberto C. Sánchez wrote: > > On Fri, Apr 24, 2015 at 10:33:11PM +0100, Dominic Hargreaves wrote: > > > Package: shorewall > > > Version: 4.6.4.3-2 > > > Severity: normal > > > > > > [note: I originally sent this on Tuesday but it doesn't seem to have > > > made it to the BTS; apologies if this somehow becomes a duplicate.] > > > > > > When shorewall loads its rules it triggers the following kernel warning: > > > > > > [ 112.699592] nf_conntrack: automatic helper assignment is deprecated > > > and it will be removed soon. Use the iptables CT target to attach helpers > > > instead. > > > > > > There are no odd rules relating to connection tracking in the shorewall > > > config. > > > > > Hi Dominic, > > > > I cannot seem to reproduce this behavior with the information you > > provided. Could you confirm that you can stil reproduce this and > > perhaps provide your /etc/shorewall directory as a tarball? Feel free > > to email it to me directly if you don't want to post it in a reply to > > the bug report. > > The problem still occurs on systems with a minimimal config - but I don't > have a tarball to hand. The systems are jessie, so perhaps the issue is > fixed in sid (maybe even with a sid kernel the original version of > shorewall?) > Hi Dominic,
Do you have libnetfilter-cthelper0 installed? If not, does installing it cause the message to stop appearing? Regards, -Roberto -- Roberto C. Sánchez http://people.connexer.com/~roberto http://www.connexer.com
signature.asc
Description: Digital signature