[FS#1083] ar71xx Kernel 4.9 PPTP Passthrough not working
LEDE Bugs
lede-bugs at lists.infradead.org
Mon Dec 4 03:33:07 PST 2017
The following task has a new comment added:
FS#1083 - ar71xx Kernel 4.9 PPTP Passthrough not working
User who did this - Martin Bouska (maabo)
----------
Hello and thank You for clearing it out!
After days of trying it to work, finally got an answer.
I decided to keep the older kernel and wait some additional time before updating to 4.9, until all these issues with conntrack helpers will be tested, **better documented** and user-friendly handled.
I understand, that the automatic loading could be a security issue.
BUT not 100% of the users are iptables config aware, so IMHO is this not the right way to getting it work.
Before it was enough to install the //kmod-nf-nathelper-extra// and all kinds of traffic passed through like charm.
But now Im not sure, if I can yet determine all of the helpers, wich will be needed in future, in order to add them manually to the .config . It is probably not secure to enable all of them yet (?); and after 1-2 years I will not rememeber how to do it, or even determine that I need to do it.
//P.S.: IMHO solution to achieve better security but keep the user friendly management could be splitting the nathelpers-extra into more specific nathelper-pptp , nathelper-sip, etc and add the iptables record automatically within installation without forcing users to do it manually. OR make Luci capable to handle the conntrack config.//
----------
More information can be found at the following URL:
https://bugs.lede-project.org/index.php?do=details&task_id=1083#comment3944
More information about the lede-bugs
mailing list