On Thu, Nov 03, 2016 at 11:13:48PM -0400, Roberto C. Sánchez wrote: > On Tue, Jul 12, 2016 at 09:24:26PM +0200, Dominic Hargreaves wrote: > > On Sat, Jul 02, 2016 at 03:42:54PM -0400, Roberto C. Sánchez wrote: > > > On Fri, Apr 24, 2015 at 10:33:11PM +0100, Dominic Hargreaves wrote: > > > > Package: shorewall > > > > Version: 4.6.4.3-2 > > > > Severity: normal > > > > > > > > [note: I originally sent this on Tuesday but it doesn't seem to have > > > > made it to the BTS; apologies if this somehow becomes a duplicate.] > > > > > > > > When shorewall loads its rules it triggers the following kernel warning: > > > > > > > > [ 112.699592] nf_conntrack: automatic helper assignment is deprecated > > > > and it will be removed soon. Use the iptables CT target to attach > > > > helpers instead. > > > > > > > > There are no odd rules relating to connection tracking in the shorewall > > > > config. > > > > > > > Hi Dominic, > > > > > > I cannot seem to reproduce this behavior with the information you > > > provided. Could you confirm that you can stil reproduce this and > > > perhaps provide your /etc/shorewall directory as a tarball? Feel free > > > to email it to me directly if you don't want to post it in a reply to > > > the bug report. > > > > The problem still occurs on systems with a minimimal config - but I don't > > have a tarball to hand. The systems are jessie, so perhaps the issue is > > fixed in sid (maybe even with a sid kernel the original version of > > shorewall?) > > > Hi Dominic, > > Do you have libnetfilter-cthelper0 installed? If not, does installing > it cause the message to stop appearing?
No, and yes installing it does get rid of the messages (I don't quite understand why... :) Cheers, Dominic.

