NetFilter
[Top] [All Lists]

Re: Debian 2.6.8/bridge/iptables/passive ftp

To: netfilter@lists.netfilter.org
Subject: Re: Debian 2.6.8/bridge/iptables/passive ftp
From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
Date: Wed, 04 Apr 2007 19:44:27 +0200
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <361462969@web.de>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: Plouf !
References: <361462969@web.de>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Mozilla Thunderbird 1.0.6 (Windows/20050716)
Hello,

spaminator@web.de a écrit :

Rebooting the bridge box left me again with an unloaded
ip_conntrack_ftp. So I made an entry in /etc/modules which caters for
the module to be loaded on (re)boot. Strange thing that, because other
modules related to iptables are being loaded automatically, although
they are not compiled into the kernel too. Are there other
"surprise"-modules that have to be loaded via /etc/modules?

Only modules related to iptables rules are loaded automatically, when needed by a table, target or match in a newly created rule. Conntrack and NAT helper modules for special protocols (FTP, IRC DCC, TFTP, H.323, SIP...) are not related to any rule, thus not loaded automatically.


<Prev in Thread] Current Thread [Next in Thread>