[Oisf-users] suricata with iptables NFQUEUE and kernel warnings for net/ipv4

Vieri rentorbuy at yahoo.com
Wed Feb 19 19:44:53 UTC 2020


On Monday, February 17, 2020, 5:39:26 PM GMT+1, Victor Julien <lists at inliniac.net> wrote: 

> I would suggest reporting this to the netfilter/netfilter-devel list.

Hi,

Would you mind taking a look at this post on the netfilter mailing list?

https://marc.info/?l=netfilter&m=158202960208464&w=2

The patch there seems to get rid of the kernel warning messages I see in syslog.
However, it also seems that using nfq in repeat mode might cause these messages. It's merely an observation that needs to be verified by testing for longer periods, but the messages don't come up when using nfq in accept mode.

Any thoughts?

Vieri


More information about the Oisf-users mailing list