[FS#1083] ar71xx Kernel 4.9 PPTP Passthrough not working

LEDE Bugs lede-bugs at lists.infradead.org
Mon Dec 4 03:33:07 PST 2017


The following task has a new comment added:

FS#1083 - ar71xx Kernel 4.9  PPTP Passthrough not working
User who did this - Martin Bouska (maabo)

----------
Hello and thank You for clearing it out!
After days of trying it to work, finally got an answer.

I decided to keep the older kernel and wait some additional time before updating to 4.9, until all these issues with conntrack helpers will be tested, **better documented** and user-friendly handled.

I understand, that the automatic loading could be a security issue. 
BUT not 100% of the users are iptables config aware, so IMHO is this not the right way to getting it work. 
Before it was enough to install the //kmod-nf-nathelper-extra// and all kinds of traffic passed through like charm.
But now Im not sure, if I can yet determine all of the helpers, wich will be needed in future, in order to add them manually to the .config . It is probably not secure to enable all of them yet (?); and after 1-2 years I will not rememeber how to do it, or even determine that I need to do it.

//P.S.: IMHO solution to achieve better security but keep the user friendly management could be splitting the nathelpers-extra into more specific nathelper-pptp , nathelper-sip, etc and add the iptables record automatically within installation without forcing users to do it manually. OR make Luci capable to handle the conntrack config.//
----------

More information can be found at the following URL:
https://bugs.lede-project.org/index.php?do=details&task_id=1083#comment3944



More information about the lede-bugs mailing list