Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-20 Thread ToddAndMargo via users
Fix it!!! This was the missing link: $tbls -t raw -A OUTPUT -p tcp --dport 21 -j CT --helper ftp Here are my new rules: -T # FTP Passive Mode stuff # raw: # # This table is used mainly for configuring exemptions from # connection tracking in combination with the NOTRACK target. # It

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-20 Thread ToddAndMargo via users
On 12/20/22 14:14, Jeffrey Walton wrote: On Tue, Dec 20, 2022 at 5:05 PM ToddAndMargo via users wrote: On 12/20/22 11:18, Barry Scott wrote: [...] I found this comment "But keep in mind this is considered a security vulnerability - that's why newer kernels changed the default value of nf_connt

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-20 Thread Jeffrey Walton
On Tue, Dec 20, 2022 at 5:05 PM ToddAndMargo via users wrote: > On 12/20/22 11:18, Barry Scott wrote: > > [...] > > I found this comment "But keep in mind this is considered a security > > vulnerability - that's why newer kernels changed the default value of > > nf_conntrack_helper to false." on >

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-20 Thread ToddAndMargo via users
On 12/20/22 11:18, Barry Scott wrote: On 20 Dec 2022, at 17:29, ToddAndMargo via users wrote: On 12/19/22 17:24, ToddAndMargo via users wrote: Hi All, # uname -r 6.0.12-300.fc37.x86_64 I have tried googling this.  I get tons of hits but nothing specific to FC37. Just noticed that I can not

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-20 Thread Barry Scott
> On 20 Dec 2022, at 17:29, ToddAndMargo via users > wrote: > > On 12/19/22 17:24, ToddAndMargo via users wrote: >> Hi All, >> # uname -r >> 6.0.12-300.fc37.x86_64 >> I have tried googling this. I get tons of hits >> but nothing specific to FC37. >> Just noticed that I can not do: >> $ curl -

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-20 Thread ToddAndMargo via users
On 12/19/22 17:24, ToddAndMargo via users wrote: Hi All, # uname -r 6.0.12-300.fc37.x86_64 I have tried googling this.  I get tons of hits but nothing specific to FC37. Just noticed that I can not do: $ curl -v ftp://ftp.adobe.com/pub/adobe/reader/win/AcrobatDC/ -o - * Connecting to 192.147.

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-20 Thread ToddAndMargo via users
On 12/19/22 22:19, Jeffrey Walton wrote: On Mon, Dec 19, 2022 at 8:24 PM ToddAndMargo via users wrote: [...] I have tried googling this. I get tons of hits but nothing specific to FC37. The latest Fedora docs are at https://docs.fedoraproject.org/en-US/fedora/latest/system-administrators-gu

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-19 Thread Barry
> On 20 Dec 2022, at 01:24, ToddAndMargo via users > wrote: > > Hi All, > > # uname -r > 6.0.12-300.fc37.x86_64 > > I have tried googling this. I get tons of hits > but nothing specific to FC37. > > Just noticed that I can not do: > > $ curl -v ftp://ftp.adobe.com/pub/adobe/reader/win/Ac

Re: FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-19 Thread Jeffrey Walton
On Mon, Dec 19, 2022 at 8:24 PM ToddAndMargo via users wrote: > > [...] > I have tried googling this. I get tons of hits > but nothing specific to FC37. The latest Fedora docs are at https://docs.fedoraproject.org/en-US/fedora/latest/system-administrators-guide/ . > Just noticed that I can not

FC37 corked my passive FTP, nf_conntrack_helper vanished

2022-12-19 Thread ToddAndMargo via users
Hi All, # uname -r 6.0.12-300.fc37.x86_64 I have tried googling this. I get tons of hits but nothing specific to FC37. Just noticed that I can not do: $ curl -v ftp://ftp.adobe.com/pub/adobe/reader/win/AcrobatDC/ -o - * Connecting to 192.147.130.111 (192.147.130.111) port 18897 Connection ti