iptables -m state --state UNTRACKED uses SNAT state instead
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
iptables (Debian) |
Fix Released
|
Unknown
|
|||
iptables (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
An input rule like -A INPUT -m addrtype -m state --state NEW,RELATED,
creates a rule that actually refers to the SNAT state.
Chain INPUT (policy ACCEPT)
[...]
whatever all -- anywhere anywhere state NEW,RELATED,SNAT
This was apparently fixed upstream in 1.4.19. I will link the debian report (700066) in a moment
ProblemType: Bug
DistroRelease: Ubuntu 13.10
Package: iptables 1.4.18-1.1ubuntu1
ProcVersionSign
Uname: Linux 3.11.0-17-generic x86_64
NonfreeKernelMo
ApportVersion: 2.12.5-0ubuntu2.2
Architecture: amd64
Date: Mon Mar 10 12:24:44 2014
MarkForUpload: True
SourcePackage: iptables
UpgradeStatus: Upgraded to saucy on 2013-11-01 (129 days ago)
Changed in iptables (Debian): | |
status: | Unknown → Fix Released |
Fixed since Ubuntu 14.04.