Mailinglist Archive: opensuse-features (362 mails)

< Previous Next >
[New: openFATE 308519] Add conntrack Tools
  • From: fate_noreply@xxxxxxx
  • Date: Fri, 11 Dec 2009 08:06:32 +0100 (CET)
  • Message-id: <feature-308519-1@xxxxxxxxxxxxxx>
Feature added by: Don Hughes (dehughes)

Feature #308519, revision 1
Title: Add conntrack Tools

openSUSE-11.3: Unconfirmed
Requester: Desirable

Requested by: Don Hughes (dehughes)

Add conntrack tools for iptables from

This application allows you to manipulate the connection tracking information
under /proc/net/nf_conntrack wiht commands with syntax similar to that of
iptables and ipset.  The tools alow you to modify the information instead of
only beinig able to list it.

They also provide a way to keep the tracking information on a backup system in
sync with the production system. 

I found that they provided a much eaier way to recover from a hung nat'ed VoIP
sip connection than the previous methods (adjusting the conntrack timeout
values to expire all the connections, rebooting, restarting interfaces, kicking
things, all of the above) i.e. conntrack -D --orig-src <ip of sip gateway>


also provided are

conntrack -L (list)

-G (get)

-D (delete)

-I (create/insert)

-E (event, sort of like tail)

-F (flush)

with a number of filter parameters to match addresses, protocols, families,
ports, etc.



openSUSE Feature:

< Previous Next >
List Navigation
This Thread
  • No further messages