Change in conntrack helpers

LnxBil

Distinguished Member
Feb 21, 2015
9,504
1,710
273
Saarland, Germany
I just noticed, that the conntrack helpers are per default off in PVE5:

Code:
$ sysctl net.netfilter.nf_conntrack_helper
net.netfilter.nf_conntrack_helper = 0

I stumbled upon this by debugging why an LXC container with an openvpn gateways does not allow sip anymore after upgrading from PVE4 to PVE5. Still have not solved my issue, but can this be related to the underlying change in the kernel with respect to conntrack helper interaction? Just setting the aforementioned parameter to 1 does unfortunately not resolve my issue.

Anyone experiencing similar issues with conntrack/nat inside LXC containers on PVE5?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!