Can't set output policy to ACCEPT_NO_TRACK

Bug #787955 reported by Andi Hechtbauer on 2011-05-25
This bug affects 2 people
Affects Status Importance Assigned to Milestone
ufw (Ubuntu)
Jamie Strandboge

Bug Description

Binary package hint: ufw

In the documentation and in /etc/default/ufw comments of ufw 0.30.1-1ubuntu1 (11.04) a default policy that does not do connection tracking is advertised, ACCEPT_NO_TRACK.

When this is used sudo ufw enable results in "ERROR: problem running ufw-init"

Digging into this (using sudo /lib/ufw/ufw-init force-reload), some more output can be seen, maybe pointing in the direction of a bug:

iptables-restore v1.4.10: Can't set policy `OUTPUT' on `ACCEPT_NO_TRACK' line 5: Bad policy name

iptables-restore v1.4.10: Couldn't load target `ACCEPT_NO_TRACK':/lib/xtables/ cannot open shared object file: No such file or directory

Related branches

Changed in ufw (Ubuntu):
status: New → Triaged
Changed in ufw (Ubuntu):
assignee: nobody → Jamie Strandboge (jdstrand)
importance: Undecided → Medium
importance: Medium → Low
Changed in ufw (Ubuntu):
status: Triaged → In Progress
Jamie Strandboge (jdstrand) wrote :

This is fixed in trunk by removing the option (it never worked).

Changed in ufw (Ubuntu):
status: In Progress → Fix Committed
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ufw - 0.33-0ubuntu1

ufw (0.33-0ubuntu1) quantal; urgency=low

  * New upstream release. Fixes the following bugs:
    - also use correct ports for DHCPv6. Thanks to Marco Davids (LP: #1007326)
    - add IPv6 limit support (LP: #951462)
    - add zh_TW translation (LP: #868195)
    - add 'show added' report (LP: #987784)
    - remove ACCEPT_NO_TRACK option since it never worked (LP: #787955)
  * debian/(after|before)6.rules.md5sum: adjust for recently missed shipped
 -- Jamie Strandboge <email address hidden> Fri, 17 Aug 2012 14:32:01 -0500

Changed in ufw (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers